<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Web Security Archives - fc12</title>
	<atom:link href="https://fc12.co.uk/category/web-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://fc12.co.uk/category/web-security/</link>
	<description>digital marketing solutions</description>
	<lastBuildDate>Wed, 23 May 2018 14:40:25 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://fc12.co.uk/wp-content/uploads/2022/03/cropped-fc12-logo-2022-1-32x32.png</url>
	<title>Web Security Archives - fc12</title>
	<link>https://fc12.co.uk/category/web-security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>3 WordPress Plugin Vulnerabilities Disclosed Yesterday</title>
		<link>https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/</link>
					<comments>https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/#respond</comments>
		
		<dc:creator><![CDATA[Fred Cardoso]]></dc:creator>
		<pubDate>Wed, 25 May 2016 10:12:57 +0000</pubDate>
				<category><![CDATA[Web Applications]]></category>
		<category><![CDATA[Web Security]]></category>
		<guid isPermaLink="false">http://fc12.co.uk/?p=350</guid>

					<description><![CDATA[<p>Wordfence found yesterday three WordPress plugin vulnerabilities that I&#8217;d like to bring your attention to, all three were CVSS severity level medium. Two of these...</p>
<p class="readmore"><a class="more-btn" href="https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/">Read More</a></p>
<p>The post <a href="https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/">3 WordPress Plugin Vulnerabilities Disclosed Yesterday</a> appeared first on <a href="https://fc12.co.uk">fc12</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Wordfence found yesterday three WordPress plugin vulnerabilities that I&#8217;d like to bring your attention to, all three were CVSS severity level medium.</p>
<p>Two of these vulnerabilities were found in the WP Fastest Cache plugin and the third one on the Caldera Forms plugin.</p>
<p><span id="more-350"></span></p>
<h3><strong>Local File Inclusion Vulnerability Severity 4.2 (Medium) and Unauthorized Options Update Vulnerability Severity 4.4 (Medium) in WP Fastest Cache</strong></h3>
<p>Wordfence Security Researcher Panagiotis Vagenas discovered both of these vulnerabilities in the <a href="https://wordpress.org/plugins/wp-fastest-cache/">WP Fastest Cache</a> plugin which they reported to the author yesterday. The Local File Inclusion vulnerability allows an attacker to execute code on the target web server or on a site visitor’s browser. This enables the attacker to steal or manipulate data, perform a denial of service attack or enable additional attack types such as <a href="https://www.wordfence.com/learn/how-to-prevent-cross-site-scripting-attacks/">Cross Site Scripting</a>. Nevertheless any website using Wordfence Firewall, were provided protection against this type of attack prior to discovery.</p>
<p>The Options Update vulnerability allows an attacker to access and make changes to the CDN (<a href="https://en.wikipedia.org/wiki/Content_delivery_network">Content Delivery Network</a>) options for the website. With this control an attacker can direct all requests for css files, images, videos, etc. to their site, allowing them to serve malicious content to visitors of the vulnerable site.</p>
<p><strong>What to do</strong>?</p>
<p>The author released a fix within an hour after Wordfence notified him of the vulnerability. If you are using WP Fastest Cache plugin on your website update it asap.</p>
<p>&nbsp;</p>
<h3>Sensitive Data Exposure Vulnerability Severity 4.3 (Medium) in Caldera Forms</h3>
<p>Wordfence Security Researcher Panagiotis Vagenas also discovered this vulnerability, which reported to the <a href="https://wordpress.org/plugins/caldera-forms/">Caldera Forms</a> author yesterday alsp. This vulnerability allows an attacker to gain access to potentially sensitive data that has been captured by a Caldera Form.</p>
<p><strong>What to do</strong>?</p>
<p>The author released a fix within hours of discovery and published a <a href="https://calderawp.com/2016/05/security-update-caldera-forms/">blog post</a> about it. If you are using this Caldera Forms plugin on your website update it asap.</p>
<p>The post <a href="https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/">3 WordPress Plugin Vulnerabilities Disclosed Yesterday</a> appeared first on <a href="https://fc12.co.uk">fc12</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://fc12.co.uk/web-security/3-wordpress-plugin-vulnerabilities-disclosed-yesterday/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
