It has a CVSS Score of 9.9. It seemed that the Wordfence team had a hard time getting a response from On the Go.

Critical Vulnerability in WPML
István Márton @ wordfence.com • 6 months ago
István Márton @ wordfence.com • 6 months ago
It has a CVSS Score of 9.9. It seemed that the Wordfence team had a hard time getting a response from On the Go.
Maciek Palmowski @ patchstack.com • 6 months ago
Patchstack has started a Patchstack academy resource hub for learning about ethical hacking and security you code.
Vladimir Smitka @ smitka.me • 7 months ago
Vladimír Smitka continues his security testing and education series related to hosting providers, this time looking at PHP configuration issues. Well worth the time to read.
Francisco Torres @ make.wordpress.org • 8 months ago
The Plugin Review team has reset the passwords for plugin authors. It appears some recent plugin vulnerabilities may have been the result of password reuse.
Vladimir Smitka @ smitka.me • 8 months ago
Here is another installment in Vladimir Smitka’s series about security and hosting providers. An interesting read.
This updates fixes two cross-site-scripting vulnerabilities and a path traversal issue.
Liam Gladdy @ advancedcustomfields.com • 8 months ago
This update includes a fair number of security fixes found as the result of an external security audit. Kudos to the ACF team for having an external audit.
Jacklyn bBiggin @ developer.woocommerce.com • 8 months ago
WooCommerce XSS vulnerability notice. It has been patched, so there is an update available.
Vladimír Smitka @ smitka.me • 8 months ago
Here is part two of Vladimír Smitka’s series where he tested various Cloud panels for managing VPS. In this installment he looks at Enhance and FlyWP, which use Docker containers, and explains why they weren’t secure and explores some of the possible fixes.