Big news from our partners at @rapydcloud.bsky.social π
We're thrilled to support the launch of Rapyd Cloud 2.0
Whatβs new:
β
Multiple site plans
β
An Agency Partnership Program
β
A revamped dashboard
π Check out their announcement: rapyd.cloud/blog/introdu...
#ManagedHosting #Cybersecurity
Posts by Patchstack
π» #CloudFest Hackathon day 2 is in full swing and the team, led by Nestor Angulo De Ugarte and John Blackbourn, is racking their brains. π§ β‘οΈ
Curious to see the results? See the final presentations tomorrow at 3:55 PM at the Ring Stage in Europa Park. π
#CFHack #CFHack2025 #cloudfest
Unauthenticated Arbitrary File Upload Vuln in Chaty Pro plugin π‘οΈ
It suffers from an arbitrary file upload vuln. An attacker can upload a malicious file and take over the site π«
It was fixed in 3.3.4 β
With Patchstack protection activated, you're already protected π‘οΈ
patchstack.com/articles/una...
Reflected XSS Patched in Essential Addons for Elementor π οΈ
It happens due to insufficient validation of the popup-selector query argument. π€
It got fixed in 6.0.15 β
If you have Patchstack protection enabled, you're already protected. π‘οΈ
patchstack.com/articles/ref...
Critical Privilege Escalation Patched in KLEO Themeβs Plugin. π
It occurs due to broken logic in the FB social login process. β
Update it immediately to at least 5.4.0 β¬οΈ
If you have Patchstack protection enabled, you're already protected. β
patchstack.com/articles/cri...
#WCAsia is just around the corner, and here at #Patchstack, we've decided to host a Capture The Flag event π©
Don't miss outβmark your calendars for 20-22 February π
There are also some amazing prizes for the best hackers out there π°
ctf.patchstack.com
π¨ Rare Case of Privilege Escalation in Admin and Site Enhancements Plugin.
It occurs due to broken logic on the βView Admin as Roleβπ€
Update it immediately to at least 7.6.3π§
If you have Patchstack protection enabled, you are already automatically protectedπ‘οΈ
patchstack.com/articles/rar...
π¨ high-priority vulnerability has been fixed in the "Better Find and Replace" plugin. It is expected to become mass exploited!
Update the plugin immediately to at least 1.6.8
If you have Patchstack protection enabled, you are already automatically protected π‘οΈ
patchstack.com/articles/pri...
Our latest newsletter is live! π
Inside, you'll find:
π° The security layer cake
π Vulnerability advisories
π° News and tips
Read it here:
preview.mailerlite.io/preview/761...
π¨ Critical Vulnerability Patched in GiveWP Plugin.
Versions 3.19.3 and below suffer from an unauthenticated PHP Object Injection vuln. π»
This was fixed in version 3.19.4, so update ASAP. π οΈ
As a paid Patchstack user you're protected from this vulnπ‘οΈ
patchstack.com/articles/cr...
Critical Vulnerabilities Found in Fancy Product Designer Plugin! π¨
It suffers from Unauthenticated Arbitrary File Upload and SQL Injection vulnerabilities. βοΈβπ₯
No patch was released. π
As a paid Patchstack user you're protected from this vulnerabilityπ‘οΈ
patchstack.com/articles/cr...
Advisory Alert: Critical Vulnerabilities Fixed in WPLMS and VibeBP! π¨
Please update to versions 1.9.9.5.3 and 1.9.9.7.7. β¬οΈ
You are also protected from this vulnerability if you are a paid Patchstack user. π‘οΈ
patchstack.com/articles/mu...
Imagine if your #WooCommerce store were hacked. It's a dreadful thought, we know, but it can happen. π±
Don't panic, though. Lana has prepared a 10-step guide to help you restore your site. πͺ
patchstack.com/articles/yo...
Our researcher, Edouard, shares fascinating insights about the most exploited WordPress threats in Q4. π΅οΈββοΈ
He also provides in-depth examples of how virtual patches work to protect against vulnerabilities. π»
patchstack.com/articles/q4...
π
revisited Patchstack HQ. He needs you to find more difficult vulns in #WordPress plugins and themes.
π
When: 17-23 Dec
π‘οΈ What: SQLi, PHP Object Injection, Insecure Deserialization
π CVSS: 7.0+
π Installs: 50+
π $4700 bounty pool
Learn more at patchstack.com/bug-bounty/
We released an advisory about Multiple Critical Vulnerabilities Patched in the Woffice Theme. π
If you use it, update it to version 5.4.15+. β¬οΈ
You're also protected from this vuln if you are a paid Patchstack user. πͺ
patchstack.com/articles/mu...
π
visited Patchstack and has a quest for you to find vulns in #WordPress plugins and themes.
π
When: 10-17 Dec
π‘οΈ What: XSS, CSRF, Arbitrary file download, privilege escalation, or sensitive data exposure
π CVSS: 6.4+
π Installs: 50+
Learn more at patchstack.com/bug-bounty/
We just released an advisory about an unauthenticated Privilege Escalation Vulnerability #vulnerability in Sweet Date Theme π¨
If you use it, update it to version 3.8.0+ if possible β¬οΈ
You're also protected from this vuln if you are a paid Patchstack user πͺ
patchstack.com/articles/un...
Authenticated RCE Patched in Rank Math SEO plugin
patchstack.com/articles/authenticated-r...
We just released an advisory about an authenticated RCE #vulnerability in Rank Math SEO plugin π»
If you use this plugin, please update it to version 1.0.232 or later. π§
You're also protected from this vuln if you are a paid Patchstack user. π
Link in the comment below π
We just launched a Black Friday special #bounty event π
π
When: 26 Nov to 08 Dev
ποΈ What: WooCommerce and alternatives, payment gateways, and plugins extending eCommerce functionality
π CVSS: 6.4+
π Installs: 50+ active installs
Learn more https://patchstack.com/bug-bounty/
We have just released an advisory about the Unauthenticated Arbitrary File Read Vulnerability in the Jobify Theme. π
Unfortunately, this vulnerability is still unpatched. π
However, all paid Patchstack users are protected from this vuln. β
patchstack.com/articles/una...
Does anyone want to spend Friday having lots of fun? Here's your chance - ctf.patchstack.com, #CTF challenge organized by @patchstack.com, but all challenges are made by the Patchstack Alliance community of #ethical #hackers, #security #researchers, and #developers π€© Of course, there are prizes! π€
Howdy π€
At High Noon (GMT) we're starting a Capture The Flag Event at @patchstack.com
In the bank, the sheriff holds some great prizes π° for the fastest hackers:
First place - $1000
Second place - $600
Third place - $400
To participate register at ctf.patchstack.com
Good luck π
We are proud sponsors of #WordCamp #Wroclaw π΅π±πͺ
Make sure to say "czeΕΔ" to @maciekpalmowski.dev. Catch his talk on security this Saturday, and snag some cool Patchstack swag while you're at it! π‘οΈπ€
Do zobaczenia π
Check out our latest interview with Hai Zhang from @litespeedtech.bsky.social π€
You've likely heard about the recent vulnerabilities in their #WordPress Plugin. π
Hai dives into how they swiftly tackled these issues and the significance of joining an mVDP. π
patchstack.com/articles/han...