Patchstack Weekly: Vulnerability news and weekly knowledge
Hi Coffigniezâ, it's another week of Patchstack Weekly update, and firstly, let's go over important vulnerabilities.
Advanced Contact form 7 DB
Vulnerability: Arbitrary File Deletion Fixed in version: 1.8.7 Number of sites affected: 90,000+ CVSS 3.0 score: 8.1 (High - Requires subscriber or higher role user authentication.)
Event Manager and Tickets Selling Plugin
Vulnerability: SQL Injection (SQLi) Fixed in version: 3.5.8 Number of sites affected: 9,000+ CVSS 3.0 score: 7.4 (High - Requires contributor or higher role user authentication.)
If you are using any of the mentioned plugins, you need to update it to the latest version as soon as possible. Websites with Patchstack installed are protected from the security issues mentioned below.
In this week's session, Robert will talk about a specific library that is being used by hundreds of WordPress plugins. What can developers do about it? How can site owners check if they are affected? Learn more from this episode.ð