View this email in your browser
Podcast Episode #12
Patchstack Weekly: Vulnerability news and weekly knowledge

Hi Coffigniez​, it's another week of Patchstack Weekly update, and firstly, let's go over important vulnerabilities.
 

Advanced Contact form 7 DB

Vulnerability: Arbitrary File Deletion
Fixed in version: 1.8.7
Number of sites affected: 90,000+
CVSS 3.0 score: 8.1 (High - Requires subscriber or higher role user authentication.)

Event Manager and Tickets Selling Plugin

Vulnerability: SQL Injection (SQLi)
Fixed in version: 3.5.8
Number of sites affected: 9,000+
CVSS 3.0 score: 7.4 (High - Requires contributor or higher role user authentication.)

If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.

You can find all the vulnerabilities from our vulnerability database
Weekly knowledge about a vulnerable library

In this week's session, Robert will talk about a specific library that is being used by hundreds of WordPress plugins. What can developers do about it? How can site owners check if they are affected? Learn more from this episode.👇

Read & Listen The Episode
Always keep your plugins updated. If possible, enable automatic updates. You can enable automatic updates with Patchstack here

If you are not protecting your WordPress site against plugin vulnerabilities yet go and start for free here.

Are you on Facebook? Join the Patchstack community and be the first to hear about new feature updates, news, and announcements.
LinkedIn
Facebook
Twitter
Spotify
Copyright © 2022 Patchstack, All rights reserved.
You are receiving this email because you opted in via our website.

Our mailing address is:
Patchstack
Akadeemia 1
Forwardspace
Parnu 80011
Estonia

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.