Vulnerability Roundup – April 2022

Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are…

Read Story

Critical RCE Vulnerability in Elementor WordPress Plugin

Security Risk: High Exploitation Level: Easy CVSS Score: 9.9 Vulnerability: Remote code execution (RCE) Patched Version: 3.6.3 On April 12th,…

Read Story

Critical RCE Vulnerability in Elementor WordPress Plugin

Security Risk: High Exploitation Level: Easy CVSS Score: 9.9 Vulnerability: Remote code execution (RCE) Patched Version: 3.6.3 On April 12th,…

Read Story

Critical Remote Code Execution Vulnerability in Elementor

On March 29, 2022, the Wordfence Threat Intelligence team initiated the disclosure process for a critical vulnerability in the Elementor…

Read Story

Critical Authentication Bypass Vulnerability Patched in SiteGround Security Plugin

On March 10, 2022 the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability we discovered in…

Read Story

Reflected XSS in Spam protection, AntiSpam, FireWall by CleanTalk

On February 15, 2022, the Wordfence Threat Intelligence team finished research on two separate vulnerabilities in Spam protection, AntiSpam, FireWall…

Read Story

How to remove classicpartnerships.com redirect malware

For the love of God make it stop..how to remove the classicpartnerships.com redirect (and others) *This guide is for removing…

Read Story

classicpartnerships.com redirect malware

We're getting inquiries about a new malware redirect affecting WordPress sites - classicpartnerships.com.  Malicious URLs: hxxps://scripts.classicpartnerships[.]com/train.js hxxps://event.classicpartnerships[.]com/c.php?id=325-34675473-24-6758 hxxps://event.classicpartnerships[.]com/s.php?id=463-24-745783-2 hxxps://event.classicpartnerships[.]com/go.php?id=5325-1285453-12-334 hxxps://rosevertical[.]online/go/mvrtkmbvmi5denbs…

Read Story

WordPress 5.9.2 Security Update Fixes XSS and Prototype Pollution Vulnerabilities

Last night, just after 6pm Pacific time, on Thursday  March 10, 2022, the WordPress core team released WordPress version 5.9.2,…

Read Story

Stored Cross-Site Scripting Vulnerability Patched in a WordPress Photo Gallery Plugin

On November 11, 2021 the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability we discovered in…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.