Tag: php
7 articles

Elementor Pro Flaw Enables Unauthenticated Code Execution
A critical vulnerability in Elementor Pro, rated CVSS 9.0, allows hackers to execute malicious code remotely - and it's surprisingly easy to exploit, thanks to a logic flaw in the plugin's Forms module. This loophole lets attackers bypass security checks and write PHP files to a public uploads directory.

vBulletin Flaw Exploits Unpatched Servers
A critical vBulletin security flaw, tracked as CVE-2026-61511, leaves unpatched servers vulnerable to attacks, allowing hackers to execute malicious PHP code and putting forum operators and their communities at risk. This exploit affects vBulletin versions 5.x and 6.x, up to 5.7.5 and 6.2.1, respectively.

Exploit for Patched vBulletin Flaw Disclosed
A newly disclosed exploit for a patched vBulletin flaw shows how an unauthenticated request can be used to execute code on an unpatched forum server, putting vulnerable sites at risk. This security threat was made public on July 27, highlighting the importance of keeping software up to date.

Attackers Exploit Joomla Extension Bugs with Perfect 10 Scores
Critical vulnerabilities in two popular Joomla extensions have been exploited in the wild, allowing attackers to gain remote control of affected sites by uploading malicious files. The Cybersecurity and Infrastructure Security Agency has sounded the alarm, adding the flaws to its Known Exploited Vulnerabilities catalog.

GitHub-Hosted Malware Targets PHP Packages in Coordinated Supply Chain Attack
Malicious code was injected into eight PHP packages on Packagist, triggering a Linux binary download from GitHub Releases via JavaScript lifecycle hooks in package.json postinstall scripts. The attack was swiftly contained, with the malicious versions removed from Packagist.

Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer
A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's release process.

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems
Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts developers and organizations relying on shared code on high alert.