The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's email.
#RESEARCH

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

Understandable online privacy & cybersecurity information to keep you and your data safe. Latest cybersecurity research & trends.

Defuse Security. Home of PIE Bin, TRENT, and more...

Recorded Future’s Insikt Group produces research that creates action to disrupt adversaries. We write on a range of cyber and geopolitical topics, including state-sponsored threat groups; financially-motivated threat actors on the darknet and criminal underground; newly emerging malware and attacker infrastructure; strategic geopolitics; and influence operations.

Unit 42 brings together world-renowned threat researchers, incident responders and security consultants to create an intelligence-driven, response-ready organization that's passionate about helping you proactively manage cyber risk.

Talos intelligence and world-class threat research team better protects you and your organization against known and emerging cybersecurity threats.

This subreddit is for technical professionals to discuss cybersecurity news, research, threats, etc.

Interactive data from scam reports including amount lost, scam types, types of scam and delivery methods.

The Barracuda blog brings you the latest news, research, and insights you can’t get anywhere else.

Cybersecurity News, Awards, eSummits, Research.

RTC security Research, talks and tools. We are researchers in cyber-security, continually educating ourselves and developing knowledge and code. By sharing what we learn, we hope to push RTC security forward.

The Intelligence and research arm of Check Point Technologies provides leading cyber threat intelligence to Check Point customers and the greater intelligence community.

The latest cybersecurity trends, best practices, security vulnerabilities, and more.

Kaspersky's threat research and reports.

Read SafeBreach’s original threat research reports and learn about updates to our Hacker’s Playbook.

Learn how to protect your ML advantage. Check out HiddenLayer’s recent releases, announcements, and musings on protecting your algorithms.

Our research findings are for everyone’s benefit.

The list of research articles compiled by SecurityScorecard.

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.

MDSec was founded on the principles that traditional security assessment describes problems, but Security Education helps fix or avoid them.

Get the intelligence you need to detect, prevent & respond to cyber threats. Read the Intel 471 cyber threat intelligence blog.

Thoughts, research, reports, and more from Truffle Security Co.