Tech Leverage

Multiple WordPress Plugins Disclosed With XSS, Authorization, and File Inclusion Flaws

Sourced from 2 publications

  • •CoreShop through 1.5.5 has an authorization bypass allowing authenticated users to act on other customers' orders via the OrderController.
  • •MultiVendorX through 5.0.19 permits vendor accounts to modify marketplace-wide settings through an improperly secured REST endpoint.
  • •Elated-mes Ambient Plugin up to 1.7 contains a critical file inclusion vulnerability rated more severe than the XSS flaws.
  • •At least seven plugins carry remotely exploitable XSS vulnerabilities, including four kutethemes products, designthemes LMS, Educavo, and Barcode Scanner.
  • •No known exploits are currently available for any of the disclosed vulnerabilities.

Sources

Was this story useful?

Curated from 2 sources. Every summary is reviewed for accuracy, but may still contain errors. We always link to original sources for verification.

Related Stories

About Meridian

Meridian is a free daily newsletter delivering signal-scored news stories with forward-looking analysis every morning. Stories are scored across six criteria (global leverage, capital impact, temporal durability, career relevance, decision utility, and narrative clarity) then assigned to Big Signal, Core, or Quick tiers.

Get Meridian in your inbox

The stories that matter, every morning at 06:00.