Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the MWP-Firewall domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/E4wU9yBtpX5OW19y/wpf202503/public_html/wp-includes/functions.php on line 6121

Deprecated: Creation of dynamic property SureCart\Licensing\Updater::$cache_key is deprecated in /home/E4wU9yBtpX5OW19y/wpf202503/public_html/wp-content/plugins/MWP-Firewall/licensing/src/Updater.php on line 22
Plugin Vulnerabilities – WP-Firewall

插件漏洞

(CVE-2025-8216) Sky Addons for Elementor Security Flaw in WordPress Sky Addons Widgets cover

(CVE-2025-8216)Sky Addons for Elementor 安全漏洞,存在于 WordPress Sky Addons Widgets 中

了解影响 Sky Addons for Elementor 插件(最高版本 3.1.4)的紧急安全漏洞。了解如何保护您的 WordPress 网站免受存储型跨站脚本 (XSS) 威胁。确定更新优先级、管理用户权限,并使用防火墙和扫描工具增强防护,打造更安全的在线体验。

(CVE-2025-48293) Geo Mashup Protect Your Site from Geo Mashup Local File Inclusion cover

(CVE-2025-48293) Geo Mashup 保护您的网站免受 Geo Mashup 本地文件包含攻击

Geo Mashup 插件中发现了一个严重的本地文件包含漏洞(版本 <= 1.13.16), posing a significant risk to WordPress sites. Update immediately and consider using managed firewalls to protect against potential attacks and safeguard your site.

[CVE-2025-6262] muse.ai Secure WordPress From Video Plugin XSS Attacks cover

[CVE-2025-6262] muse.ai 保护 WordPress 视频插件免受 XSS 攻击

了解 muse.ai 插件中的存储型 XSS 漏洞,增强 WordPress 安全性。了解贡献者如何利用未过滤的短代码,并探索切实可行的网站保护措施,包括用户角色管理和使用 Web 应用防火墙。即使面对低优先级威胁,也要保持警惕,保障您的在线形象。

XSS Vulnerability Fixed in Slider Revolution Plugin Update cover

Slider Revolution 插件更新中修复了 XSS 漏洞

超过 900 万个网站使用的流行 Slider Revolution 插件最近面临未经身份验证的跨站点脚本 (XSS) 漏洞。我们迅速采取行动,发布了 6.7.0 和 6.7.11 版本来解决该问题。此事件强调了对 WordPress 插件进行定期安全更新和审核的迫切需要。