Tag: xss
4 articles

BdThemes Plugins Targeted in Supply Chain Attack
A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

WordPress Fixes Pre-Auth XSS Flaw That Enables PHP Code Execution
WordPress has patched a high-severity flaw that could let attackers inject malicious code into your site - and it's crucial you update ASAP, as 41.2% of all websites are potentially vulnerable.

Russian Hackers Exploit Zimbra Flaw for Widespread Email Theft
Russian hackers have exploited a Zimbra flaw, CVE-2025-66376, to steal emails from targeted organizations, allowing them to automatically collect a victim's last 90 days of email without requiring any interaction. This alarming vulnerability was weaponized by the Russian state-sponsored group Laundry Bear using a combination of phishing and specially crafted HTML emails.

Microsoft Exchange Servers Targeted by Active CVE-2026-42897 Exploit
Microsoft warns of a high-severity vulnerability, CVE-2026-42897, in its Exchange Servers, allowing attackers to spoof network communications via a cleverly crafted email. This cross-site scripting flaw has been actively exploited, earning a concerning CVSS score of 8.1.