A critical security vulnerability has been revealed in the widely used WordPress plugin called Ultimate Member, which is installed on over 200,000 websites.
The vulnerability CVE-2024-1071 has a high CVSS score of 9.8 out of 10. It was discovered and reported by security researcher Christiaan Swiers.
By infosecbulletin
/ Tuesday , October 29 2024
The Indian Cyber Crime Coordination Centre (I4C) has warned about illegal payment gateways set up by transnational cyber criminals using...
Read More
By infosecbulletin
/ Monday , October 28 2024
With a festive look and the participation of more than one hundred participants from Bangladesh cyber industry, another successful cyber...
Read More
By infosecbulletin
/ Monday , October 28 2024
Fazle Hassan Anik hacked girls' Facebook accounts to steal sensitive pictures, which he used to blackmail them for money. He...
Read More
By infosecbulletin
/ Sunday , October 27 2024
Bangladeshi Social media posts have raised concerns about unauthorized withdrawals from bank accounts, affecting at least 7 to 8 people...
Read More
By infosecbulletin
/ Friday , October 25 2024
Cybersecurity researcher Jeremiah Fowler found a non-password-protected database with 115,000 records linked to the UN Trust Fund to End Violence...
Read More
By infosecbulletin
/ Friday , October 25 2024
Cisco announced updates on Wednesday to fix a security flaw in its Adaptive Security Appliance (ASA) that is currently being...
Read More
By infosecbulletin
/ Wednesday , October 23 2024
White hat hackers at the Pwn2Own Ireland 2024 contest by Trend Micro's Zero Day Initiative earned $500,000 on the first...
Read More
By infosecbulletin
/ Tuesday , October 22 2024
In today's rapidly changing cybersecurity environment, organizations encounter numerous complex threats targeting endpoints and networks. CrowdStrike and Fortinet have partnered...
Read More
By infosecbulletin
/ Tuesday , October 22 2024
Sophos, based in the UK, is to acquire Secureworks, a Nasdaq-listed company, for $859 million in cash from Dell Technologies....
Read More
By infosecbulletin
/ Monday , October 21 2024
The Internet Archive was breached again, this time through their Zendesk email support platform, following warnings that threat actors had...
Read More
WordPress security company Wordfence recently published an advisory stating that the plugin is vulnerable to SQL Injection when using the ‘sorting’ parameter in versions 2.1.3 to 2.8.2. This vulnerability is due to insufficient escaping on the user supplied parameter and lack of proper preparation on the SQL query.
Attackers without authentication can take advantage of this problem to add extra SQL queries to existing ones and access important data from the database.
The issue only affects users who have enabled the “Enable custom table for usermeta” option in the plugin settings.
A fix for the flaw was released by the plugin developers on February 19, after a responsible disclosure on January 30, 2024.