WordPress Vulnerabilities & Patch Roundup — July 2022

Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises.

To help educate website owners on emerging threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month.

Youzify – Unauthenticated SQLi
Security Risk: Critical
Vulnerability: SQL Injection
Exploitation Level: Can be exploited remotely without authentication.

Continue reading WordPress Vulnerabilities & Patch Roundup — July 2022 at Sucuri Blog.

More great articles

Wordfence Intelligence Weekly WordPress Vulnerability Report (November 27, 2023 to December 3, 2023)

Wordfence just launched its bug bounty program. Through December 20th 2023, all researchers will earn 6.25x our normal bounty rates…

Read Story

High-Severity Vulnerabilities Patched in LearnPress

On March 16, 2020, LearnPress – WordPress LMS Plugin, a WordPress plugin with over 80,000 installations, patched a high-severity vulnerability…

Read Story

PSA: Nearly 5 Million Attacks Blocked Targeting 0-Day in BackupBuddy Plugin

Late evening, on September 6, 2022, the Wordfence Threat Intelligence team was alerted to the presence of a vulnerability being…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.