Vulnerability Reports
Dated disclosures of plugin, theme, and core vulnerabilities, and how MalCare responds.
27 articles · page 2 of 3

MalCare’s Atomic Security Outsmarts RegistrationMagic Privilege Escalation Vulnerability
Learn how MalCare blocked the RegistrationMagic privilege-escalation vulnerability, who was at risk, and which remediation steps site owners needed.
MalCare Proactively Blocks Attacks on LayerSlider SQL Injection Vulnerability
In our recent data, we have seen a number of attacks trying to exploit a SQL injection vulnerability, recently discovered in the LayerSlider plugin.
MalCare Ensures Proactive Protection Against WP-Members XSS Vulnerability
MalCare continues to protect its customer sites from all kinds of attacks, even the ones exploiting zero-day vulnerabilities. The recent stored cross-site
MalCare Proactively Defends Against Icegram Express SQL Injection Vulnerability
MalCare’s recent data has revealed numerous attempts to exploit a newly found SQL injection vulnerability in the Icegram Express plugin. Attackers commonly
MalCare Ensures Unmatched Protection Against User Registration Privilege Escalation Vulnerability
Learn how the User Registration plugin privilege escalation flaw exposed WordPress sites and how MalCare's firewall blocks exploitation.
MalCare Stands Strong Against WP Activity Log Premium SQL Injection Vulnerability
Understand the WP Activity Log Premium SQL injection vulnerability, affected versions, potential impact, and how MalCare helps block exploitation.
MalCare Shields Over 6,000,000 Sites Against Critical Vulnerability in WPForms Plugin
On October 23rd, 2024, a critical vulnerability was discovered in the WPForms plugin. This vulnerability affects versions of the plugin from v1.8.4 up to and
MalCare Protects Against Critical Vulnerability In Really Simple Security Plugin
Learn how the critical Really Simple Security authentication bypass worked, which versions were affected, and how to protect your WordPress site.
MalCare Proactively Blocks Remote Code Execution Exploits in WPML Plugin
On June 19th, 2024, a critical security flaw was discovered in the WPML WordPress plugin, affecting all versions up to 4.6.12. This vulnerability is severe,
MalCare’s Atomic Security Thwarts Attacks Exploiting Critical Yoast SEO XSS Vulnerability
A serious cross-site scripting (XSS) vulnerability has been discovered in the Yoast SEO plugin, where attackers can compromise a website if a site
MalCare Blocks Critical Privilege Escalation Vulnerability in Post Grid and Gutenberg Blocks Plugin
Review the critical Post Grid and Gutenberg Blocks privilege-escalation flaw, affected versions, technical details, and protection steps.
This Vulnerability In Your WP Live Chat Support Plugin Lets Hackers Compromise Your Site!
Do you have a WP live chat support plugin? You should know about a vulnerability that can let hackers compromise your site. Read on!