Aggregator
Lazarus Group Exploits Trusted Apps for Data Theft via Dropbox
7 months 2 weeks ago
In an alarming development, North Korea’s infamous Lazarus Group has been linked to a global cyber espionage campaign, code-named Operation Phantom Circuit. Beginning in September 2024, this operation exploited trusted software development tools to infiltrate systems worldwide, targeting cryptocurrency and technology developers. The campaign’s advanced obfuscation techniques and infrastructure demonstrate a significant evolution in the […]
The post Lazarus Group Exploits Trusted Apps for Data Theft via Dropbox appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Aman Mishra
1-Click Phishing Campaign Targets High-Profile X Accounts
7 months 2 weeks ago
In an attack vector that's been used before, threat actors aim to commit crypto fraud by hijacking highly followed users, thus reaching a broad audience of secondary victims.
Elizabeth Montalbano, Contributing Writer
Black Hat USA
7 months 2 weeks ago
CVE-2025-23590 | Burtay Arat Dezdy Plugin up to 1.0 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in Burtay Arat Dezdy Plugin up to 1.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-23590. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23582 | Haider Ali Bulk Categories Assign Plugin up to 1.0 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in Haider Ali Bulk Categories Assign Plugin up to 1.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-23582. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24630 | MantraBrain Sikshya LMS Plugin up to 0.0.21 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in MantraBrain Sikshya LMS Plugin up to 0.0.21 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24630. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24631 | PhiloPress BP Email Assign Templates Plugin up to 1.5 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in PhiloPress BP Email Assign Templates Plugin up to 1.5 on WordPress. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24631. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23581 | Digital Zoom Studio Demo User DZS Plugin up to 1.1.0 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Digital Zoom Studio Demo User DZS Plugin up to 1.1.0 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23581. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24656 | Realtyna Provisioning Plugin up to 1.2.2 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability classified as problematic has been found in Realtyna Provisioning Plugin up to 1.2.2 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-24656. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24707 | GT3 Photo Gallery Plugin up to 2.7.7.24 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in GT3 Photo Gallery Plugin up to 2.7.7.24 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24707. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24781 | WPJobBoard Plugin up to 5.10.1 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in WPJobBoard Plugin up to 5.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24781. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24676 | Metatagg Custom WP Store Locator Plugin up to 1.4.7 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in Metatagg Custom WP Store Locator Plugin up to 1.4.7 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-24676. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-24660 | wp.insider Simple Membership Custom Messages Plugin up to 2.4 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability has been found in wp.insider Simple Membership Custom Messages Plugin up to 2.4 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-24660. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23561 | MLL Audio Player MP3 Ajax Plugin up to 0.7 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability has been found in MLL Audio Player MP3 Ajax Plugin up to 0.7 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-23561. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-23527 | Hemnath Mouli WC Wallet Plugin up to 2.2.0 on WordPress authorization
7 months 2 weeks ago
A vulnerability classified as problematic was found in Hemnath Mouli WC Wallet Plugin up to 2.2.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-23527. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-23491 | vikashsrivastava1111989 VSTEMPLATE Creator Plugin up to 2.0.2 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability was found in vikashsrivastava1111989 VSTEMPLATE Creator Plugin up to 2.0.2 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-23491. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24646 | Maxim Glazunov XML for Avito Plugin up to 2.5.2 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Maxim Glazunov XML for Avito Plugin up to 2.5.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-24646. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-22775 | idIA Tech Catalog Importer/Scraper & Crawler Plugin up to 5.1.3 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in idIA Tech Catalog Importer and Scraper & Crawler Plugin up to 5.1.3 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-22775. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-24684 | Ederson Peka Media Downloader Plugin up to 0.4.7.5 on WordPress cross site scripting
7 months 2 weeks ago
A vulnerability classified as problematic was found in Ederson Peka Media Downloader Plugin up to 0.4.7.5 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-24684. The attack can be launched remotely. There is no exploit available.
vuldb.com