Vulnerability Summary for the Week of October 21, 2024

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source Info Patch Info
Admin–Verbalize WP
 
Unrestricted Upload of File with Dangerous Type vulnerability in Admin Verbalize WP Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through 1.0. 2024-10-23 10 CVE-2024-49668 audit@patchstack.com
 
advancedcoding–Comments wpDiscuz
 
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. 2024-10-25 9.8 CVE-2024-9488 security@wordfence.com
This article has been indexed from Bulletins

Read the original article: