writeups.xyz writeups.xyz / Wordfence

Title Vulnerabilities Programs Authors
WordPress GiveWP POP to RCE (CVE-2024-5932)
WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)
$4,998 Bounty Awarded and 100,000 WordPress Sites Protected Against Unauthenticated Remote Code Execution Vulnerability Patched in GiveWP WordPress Plugin
Exploiting authorization by nonce in WordPress plugins
The Dark Side of Contact Forms: How I Identified 7 CVEs in WordPress Plugins
CVE-2024-0685 Ninja Contact Forms Data Export SQLi