Aggregator
CVE-2025-0308 | Ultimate Member Plugin up to 2.9.1 on WordPress sql injection
CVE-2025-0318 | Ultimate Member Plugin up to 2.9.1 on WordPress information disclosure
CVE-2025-0842 | needyamin Library Card System 1.0 Login admin.php email/password sql injection
CVE-2024-12385 | WP Abstracts Plugin up to 2.7.2 on WordPress cross-site request forgery
CVE-2025-24680 | WpMultiStoreLocator WP Multi Store Locator Plugin up to 2.4.7 on WordPress cross site scripting
CVE-2025-0880 | Codezips Gym Management System 1.0 updateplan.php planid sql injection
CVE-2025-0721 | needyamin image_gallery 1.0 /view.php username cross site scripting
CVE-2025-0722 | needyamin image_gallery 1.0 Cover Image /admin/gallery.php image unrestricted upload
CVE-2025-0536 | 1000 Projects Attendance Tracking Management System 1.0 /admin/edit_action.php attendance_id sql injection
CVE-2025-0541 | Codezips Gym Management System 1.0 edit_member.php name sql injection
CVE-2024-12071 | Evergreen Content Poster Plugin up to 1.4.4 on WordPress authorization
The compliance illusion: Why your company might be at risk despite passing audits
For many CISOs, compliance can feel like a necessary evil and a false sense of security. While frameworks like ISO 27001, SOC 2, and PCI DSS offer structured guidelines, they don’t automatically equate to strong cybersecurity. The challenge? Many organizations focus on checking the compliance box rather than ensuring their controls are effective. The problem isn’t compliance itself, it’s the mindset. Too often, security teams scramble to pass an audit, only to return to business … More →
The post The compliance illusion: Why your company might be at risk despite passing audits appeared first on Help Net Security.
Job Application Spear Phishing
Starting in Q3 2024, Cofense Intelligence detected an ongoing campaign targeting employees working in social media and marketing positions. In this campaign, marked employees were encouraged to apply to a social media manager position in a Fortune 500 company. Meta, Coca-Cola, PayPal, and other brand name companies were spoofed to send fake job applications to prospects.
The post Job Application Spear Phishing appeared first on Security Boulevard.