ব্লগ

2025 10 15zip attachmentscve202511701 1

Zip Attachments Plugin Authorization Bypass Risk//Published on 2025-10-15//CVE-2025-11701

Urgent guide to CVE-2025-11701 Zip Attachments vulnerability, unauthenticated disclosure, and mitigations.

2025 10 15external logincve202511177 1

External Login Plugin Unauthenticated SQL Injection Risk//Published on 2025-10-15//CVE-2025-11177

Urgent WordPress CVE-2025-11177 unauthenticated SQLi guide for External Login plugin remediation

2025 10 15oceanpayment creditcard gatewaycve202511728 1

Critical Oceanpayment Plugin Allows Order Status Tampering//Published on 2025-10-15//CVE-2025-11728

Urgent advisory Oceanpayment Gateway <=6.0 unauthenticated order status updates and mitigations

2025 10 15ownid passwordless logincve202510294 1

Critical OwnID Passwordless Plugin Authentication Bypass//Published on 2025-10-15//CVE-2025-10294

Urgent WordPress security guide: mitigate unauthenticated OwnID Passwordless login bypass CVE-2025-10294 <=1.3.4

2025 10 15wpbakery page buildercve202511160

Critical WPBakery Stored Cross Site Scripting Risk//Published on 2025-10-15//CVE-2025-11160

Urgent patch and mitigation guide for WPBakery stored XSS CVE-2025-11160

2025 10 15ova adventcve20258561 1

Authenticated Stored XSS in Ova Advent Plugin//Published on 2025-10-15//CVE-2025-8561

Ova Advent stored XSS advisory with WP-Firewall mitigations and patch guidance.

2025 10 15funkitoolscve202510301 1

FunKItools CSRF Enables Settings Takeover//Published on 2025-10-15//CVE-2025-10301

Guide for WordPress admins on FunKItools CSRF vulnerability CVE-2025-10301 and practical WAF mitigations.

2025 10 15onoffice for wp websitescve202510045 2

Critical Authenticated SQL Injection in onOffice Plugin//Published on 2025-10-15//CVE-2025-10045

Explains authenticated SQL injection in onOffice for WP-Websites plugin and practical mitigations

2025 10 15urlyar url shortnercve202510133

Authenticated Stored XSS in URLYar Plugin//Published on 2025-10-15//CVE-2025-10133

Authenticated stored XSS in URLYar <=1.1.0 CVE-2025-10133 with mitigations and WP Firewall protections