11 Oct 2021

Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability in Cooked WordPress Plugin

Several days ago we had what looked to be a hacker probing for usage of a commercial WordPress plugin, Cooked Pro, on one of our websites, by the requesting the following file:

/wp-content/plugins/cooked-pro/modules/dropzone/dropzone.min.css [Read more]