ব্লগ

2025 10 15theme importercve202510312 2

Critical CSRF Vulnerability in Theme Importer Plugin//Published on 2025-10-15//CVE-2025-10312

Theme Importer CSRF vulnerability CVE-2025-10312 mitigation, detection, and WAF-based protection.

2025 10 15ownid passwordless logincve202510294 2

Critical OwnID Passwordless Authentication Bypass//Published on 2025-10-15//CVE-2025-10294

Urgent security advisory on OwnID Passwordless Login bypass CVE-2025-10294 with mitigations

2025 10 15tariffuxxcve202510682

Authenticated Contributor SQL Injection in Tariffuxx//Published on 2025-10-15//CVE-2025-10682

Authenticated Contributor SQL injection in TARIFFUXX <=1.4 (CVE-2025-10682) with mitigations.

2025 10 15demo import kitcve202510051 1

Authenticated Arbitrary Upload in Demo Import Kit//Published on 2025-10-15//CVE-2025-10051

Urgent guide to mitigating WordPress authenticated admin arbitrary file uploads in Demo Import Kit

2025 10 15wp bookwidgetscve202510139

Authenticated Stored XSS in BookWidgets Plugin//Published on 2025-10-15//CVE-2025-10139

Stored XSS in WP BookWidgets <=0.9 exposed to Contributor users; mitigation guide with WP-Firewall

2025 10 15zip attachmentscve202511701 1

Zip Attachments Plugin Authorization Bypass Risk//Published on 2025-10-15//CVE-2025-11701

Urgent guide to CVE-2025-11701 Zip Attachments vulnerability, unauthenticated disclosure, and mitigations.

2025 10 15external logincve202511177 1

External Login Plugin Unauthenticated SQL Injection Risk//Published on 2025-10-15//CVE-2025-11177

Urgent WordPress CVE-2025-11177 unauthenticated SQLi guide for External Login plugin remediation

2025 10 15oceanpayment creditcard gatewaycve202511728 1

Critical Oceanpayment Plugin Allows Order Status Tampering//Published on 2025-10-15//CVE-2025-11728

Urgent advisory Oceanpayment Gateway <=6.0 unauthenticated order status updates and mitigations

2025 10 15ownid passwordless logincve202510294 1

Critical OwnID Passwordless Plugin Authentication Bypass//Published on 2025-10-15//CVE-2025-10294

Urgent WordPress security guide: mitigate unauthenticated OwnID Passwordless login bypass CVE-2025-10294 <=1.3.4

2025 10 15wpbakery page buildercve202511160

Critical WPBakery Stored Cross Site Scripting Risk//Published on 2025-10-15//CVE-2025-11160

Urgent patch and mitigation guide for WPBakery stored XSS CVE-2025-11160