ব্লগ

2025 10 15onoffice for wp websitescve202510045 1

Editor Level SQL Injection in onOffice Plugin//Published on 2025-10-15//CVE-2025-10045

Authenticated SQL injection CVE-2025-10045 in onOffice for WP-Websites <=5.7; detection, mitigation, WP-Firewall protection.

2025 10 15quick featured imagescve202511176

Critical IDOR in Quick Featured Images Plugin//Published on 2025-10-15//CVE-2025-11176

Covers Quick Featured Images IDOR CVE-2025-11176 risks, detection, remediation, and protection with WP-Firewall.

2025 10 15theme importercve202510312 1

Critical CSRF Vulnerability in Theme Importer//Published on 2025-10-15//CVE-2025-10312

WordPress Theme Importer CSRF CVE-2025-10312 risk and practical mitigations for admins

2025 10 15external logincve202511177

Unauthenticated SQL Injection in External Login Plugin//Published on 2025-10-15//CVE-2025-11177

Urgent steps to patch unauthenticated SQL injection in External Login plugin CVE-2025-11177

2025 10 15funkitoolscve202510301

FunKItools CSRF Permits Unauthorized Settings Modification//Published on 2025-10-15//CVE-2025-10301

WordPress CSRF vulnerability in FunKItools detection mitigation and WAF protection guidance

2025 10 15digisellercve202510141

Authenticated Contributor Stored XSS in Digiseller//Published on 2025-10-15//CVE-2025-10141

Urgent WordPress vulnerability: Digiseller <=1.3.0 stored XSS CVE-2025-10141 with mitigations

2025 10 15quick social logincve202510140

Authenticated Stored XSS in Quick Social Login//Published on 2025-10-15//CVE-2025-10140

Urgent guide to mitigating stored XSS CVE-2025-10140 in Quick Social Login for WordPress

2025 10 15yourmembership single sign oncve202510648

YourMembership SSO Unauthenticated Access Exposes Data//Published on 2025-10-15//CVE-2025-10648

Critical advisory on YM SSO Login CVE-2025-10648 unauthenticated data exposure and mitigations

2025 10 15topbarcve202510300

TopBar Plugin CSRF Enables Unauthorized Settings Changes//Published on 2025-10-15//CVE-2025-10300

Urgent CSRF vulnerability in TopBar <=1.0.0 CVE-2025-10300 with immediate mitigations and virtual patching

2025 10 15zip attachmentscve202511692

Authorization Bypass in Zip Attachments Plugin//Published on 2025-10-15//CVE-2025-11692

CVE-2025-11692 Zip Attachments vulnerability analysis with mitigation and WP-Firewall protection