Shawn DeWolfe Consulting
  • Services
    • WordPress Web Design
    • WordPress Support
    • WordPress Hosting
    • Performance Boost
    • Writing
  • AI Agency
  • Web Development
        • Plugin Development

          We do WordPress plugins. Read More
        • Pixel to Viewport CSS

          Convert CSS. Read More
        • Integrations

          We build integreations with other systems via API calls and API creation. Read More
  • Portfolio
    • Portfolio
    • Web Development
    • The Really Old Portfolio
  • About
    • Blog
    • Victoria Web Designers
    • Partnerships
    • Hey Shawn!
    • Interesting Finds
    • Cool Coding Tricks
  • Contact
Select Page

Backup and Staging by WP Time Capsule < 1.21.16 – Authentication Bypass

Jan 14, 2020 | WordPress Vulnerabilities

Proof of Concept It is possible to login as an administrator on the site due to logical mistakes in the code. The issue resides in wptc-cron-functions.php line 12 where it parses the request. This parse_request function calls the function decode_server_request_wptc...

Import Users From CSV with Meta 1.15 – Unauthorised Authenticated Users Export

Jan 3, 2020 | WordPress Vulnerabilities

DescriptionThe export_users_csv function, registered as an authenticated AJAX call and allowing to export users, was missing the authorisation/capability check. CSRF check was in place, reducing the severity of the issue. Only version 1.15 seems to be affected as the...

ElegantThemes (divi, extra, divi-builder < 4.0.10) – Authenticated Code Injection

Jan 3, 2020 | WordPress Vulnerabilities

Description”A code injection vulnerability was discovered by our team during a routine code audit that could allow logged in contributors, authors and editors to execute a small set of PHP functions.” Affected: Divi version 3.23 and above, Extra 2.23 and...
GDPR Cookie Compliance <= 4.0.2 – Authenticated Settings Reset

GDPR Cookie Compliance <= 4.0.2 – Authenticated Settings Reset

Dec 27, 2019 | WordPress Vulnerabilities

DescriptionThe gdpr_cookie_compliance_reset_settings AJAX action registered for authenticated users lacks authorisation and CSRF checks, allowing unauthorised authenticated users to call it, which would result in the settings being reset.

The Best of 2019 – The Call

Dec 27, 2019 | Uncategorized

We are looking for the best projects from 2019. Do you have something you’re proud of? Tell us about it!
« Older Entries
Next Entries »

Related Pages

  • #5363 (no title)
  • Index Check
  • WordPress Development & Web Design
  • MVP Prototyping With A Content Management System
  • Thank You For Your Purchase
  • Date Formats for PHP
  • Get A One-Pager Website
  • Partnerships
  • Domain Name Registration
  • Include Base-64 Encoded Binary Image Data (data URI scheme) in Inline Cascading Style Sheets (CSS)
  • COVID19 Response
  • Product Support
  • Request A Quote
  • Contact Us
  • Is Your Content Ready For 2023?
  • Go Daddy
  • Doctor’s Form
  • Take Our Survey & Enter To Win!
  • Thanks!
  • Get On Google!
  • Internal
  • Test
  • Services
  • Start
  • Hey Shawn!
  • Cool Coding Tricks
  • Opportunities : Jobs, Contracts and Code Bounties
  • Join Our Newsletter…. When We Get It Going
  • Get A Dentistry Website
  • Doctors: Book Patients Online
  • Get An Optometry Website
  • WordPress Web Design | Putting Business Online
  • Web Design in Duncan BC
  • Web Design in Tofino BC
  • Web Design in Victoria BC
  • News and Information You Can Use
  • About
  • WordPress Support
  • Help!
  • Web Development
  • Other Services
  • Website Design
  • Web Design
  • Portfolio
  • Contact The WordPress Experts at Shawn DeWolfe Consulting
  • Blog
  • Et Cetera

Other Links

  • Request A Quote
  • Website Design
  • WordPress Hosting
  • WordPress Support
  • Performance Boosting
  • Other Services
  • Domain Name Registration
  • Counsellor Web Design Suite
  • Tourism Web Design Suite
  • More on Managed WordPress

Our Policies

  • Our Policies and Practices
  • Market Competition Policy
  • Privacy Policy
Request A Quote Contact us Phone: 1-844-493-2321 Web321: WordPress Design in Victoria
  • Facebook
  • Instagram
  • X (Twitter)
  • RSS

Designed by Elegant Themes | Powered by WordPress