Vulnerability: Unauthenticated Stored Cross-Site Scripting (XSS) Fixed in version: 3.1 Number of sites affected: 20,000+ CVSS 3.0 score: 8.2 (High - Can be exploited remotely without any authentication.)
PHP Everywhere
Vulnerability: Remote Code Execution (RCE) Fixed in version: 3.0.0 Number of sites affected: 30 000+ CVSS 3.0 score: 9.9 (Critical - Requires contributor or higher role user authentication.)
If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.