Vulnerability Reports
Dated disclosures of plugin, theme, and core vulnerabilities, and how MalCare responds.
34 articles · page 2 of 3

MalCare blocks attacks on vulnerable Bricks Theme Builder v1.9.6
MalCare blocked more than 26,000 attacks exploiting an RCE flaw in Bricks Builder 1.9.6. Learn the risk and required response.
MalCare Proactively blocks 100,000+ attacks Targeting Popup Builder XSS vulnerability
Learn how attackers exploited the Popup Builder XSS vulnerability, which sites were at risk, and how MalCare protected customers.
MalCare Proactively Blocks 10,000+ Attacks Targeting LiteSpeed Cache XSS Vulnerability
MalCare blocked more than 10,000 attacks exploiting a LiteSpeed Cache XSS flaw. Learn the risk, symptoms, and safest response.
MalCare’s Atomic Security Outsmarts RegistrationMagic Privilege Escalation Vulnerability
Learn how MalCare blocked the RegistrationMagic privilege-escalation vulnerability, who was at risk, and which remediation steps site owners needed.
MalCare Proactively Blocks Attacks on LayerSlider SQL Injection Vulnerability
In our recent data, we have seen a number of attacks trying to exploit a SQL injection vulnerability, recently discovered in the LayerSlider plugin.
MalCare Ensures Proactive Protection Against WP-Members XSS Vulnerability
MalCare continues to protect its customer sites from all kinds of attacks, even the ones exploiting zero-day vulnerabilities. The recent stored cross-site
MalCare Proactively Defends Against Icegram Express SQL Injection Vulnerability
MalCare’s recent data has revealed numerous attempts to exploit a newly found SQL injection vulnerability in the Icegram Express plugin. Attackers commonly
MalCare Ensures Unmatched Protection Against User Registration Privilege Escalation Vulnerability
Learn how the User Registration plugin privilege escalation flaw exposed WordPress sites and how MalCare's firewall blocks exploitation.
MalCare Stands Strong Against WP Activity Log Premium SQL Injection Vulnerability
Understand the WP Activity Log Premium SQL injection vulnerability, affected versions, potential impact, and how MalCare helps block exploitation.
MalCare Shields Over 6,000,000 Sites Against Critical Vulnerability in WPForms Plugin
On October 23rd, 2024, a critical vulnerability was discovered in the WPForms plugin. This vulnerability affects versions of the plugin from v1.8.4 up to and
MalCare Protects Against Critical PHP Object Injection Vulnerability in FluentSMTP
On November 22nd, 2024, a critical vulnerability was discovered in the FluentSMTP plugin. This vulnerability affects all versions of the plugin including
What the CleanTalk Vulnerability Revealed About Virtual Patching
Last week, we were helping a new MalCare customer with their site.