Shawn DeWolfe Consulting
MENUMENU
  • Services
    • WordPress Web Design
    • WordPress Support
    • WordPress Hosting
    • Performance Boost
    • Writing
  • AI Agency
  • Web Development
        • Plugin Development

          We do WordPress plugins. Read More
        • Pixel to Viewport CSS

          Convert CSS. Read More
        • Integrations

          We build integreations with other systems via API calls and API creation. Read More
  • Portfolio
    • Portfolio
    • Web Development
    • The Really Old Portfolio
  • About
    • Blog
    • Victoria Web Designers
    • Partnerships
    • Hey Shawn!
    • Interesting Finds
    • Cool Coding Tricks
  • Contact
Select Page

Backup and Staging by WP Time Capsule < 1.21.16 – Authentication Bypass

Jan 14, 2020 | WordPress Vulnerabilities

Proof of Concept It is possible to login as an administrator on the site due to logical mistakes in the code. The issue resides in wptc-cron-functions.php line 12 where it parses the request. This parse_request function calls the function decode_server_request_wptc...

Import Users From CSV with Meta 1.15 – Unauthorised Authenticated Users Export

Jan 3, 2020 | WordPress Vulnerabilities

DescriptionThe export_users_csv function, registered as an authenticated AJAX call and allowing to export users, was missing the authorisation/capability check. CSRF check was in place, reducing the severity of the issue. Only version 1.15 seems to be affected as the...

ElegantThemes (divi, extra, divi-builder < 4.0.10) – Authenticated Code Injection

Jan 3, 2020 | WordPress Vulnerabilities

Description”A code injection vulnerability was discovered by our team during a routine code audit that could allow logged in contributors, authors and editors to execute a small set of PHP functions.” Affected: Divi version 3.23 and above, Extra 2.23 and...
GDPR Cookie Compliance <= 4.0.2 – Authenticated Settings Reset

GDPR Cookie Compliance <= 4.0.2 – Authenticated Settings Reset

Dec 27, 2019 | WordPress Vulnerabilities

DescriptionThe gdpr_cookie_compliance_reset_settings AJAX action registered for authenticated users lacks authorisation and CSRF checks, allowing unauthorised authenticated users to call it, which would result in the settings being reset.
WP Maintenance <= 5.0.5 – Cross-Site Request Forgery to Stored Cross-Site Scripting

WP Maintenance <= 5.0.5 – Cross-Site Request Forgery to Stored Cross-Site Scripting

Nov 28, 2019 | WordPress Vulnerabilities

<html> <body> <form action=”http://URL/wp-admin/admin.php?page=wp-maintenance” method=”POST”> <input type=”hidden” name=”action” value=”update_general” /> <input...
Safe SVG < 1.9.6 – XSS Protection Bypass

Safe SVG < 1.9.6 – XSS Protection Bypass

Nov 8, 2019 | WordPress Vulnerabilities

Video POC (for <= 1.9.4): https://drive.google.com/open?id=19-sin0HB97L0tPMUAaGjgE5KjP4lXSuw Create a SVG with payload below to trigger XSS: “`<?xml version=”1.0″ standalone=”no”?> <svg viewBox=”0 0 100 100″...
« Older Entries
Next Entries »

Other Links

  • Request A Quote
  • Website Design
  • WordPress Hosting
  • WordPress Support
  • Performance Boosting
  • Other Services
  • Domain Name Registration
  • Counsellor Web Design Suite
  • Tourism Web Design Suite
  • More on Managed WordPress

Our Policies

  • Our Policies and Practices
  • Market Competition Policy
  • Privacy Policy
Request A Quote Contact us Phone: 1-844-493-2321 Web321: WordPress Design in Victoria
  • Facebook
  • Instagram
  • Twitter
  • RSS

Designed by Shawn DeWolfe Consulting