Hi,
I am currently experiencing two significant issues with tdsportsx.com that require immediate attention:
1. Security Risk for Xstore Core Plugin:
I have received a notification from my hosting portal indicating a security risk associated with the Xstore Core Plugin. This is concerning, and I would appreciate it if you could investigate and resolve this issue as soon as possible to ensure the security of my website.
Here is the warning message:
Security risk: sqli. The plugin contains a vulnerability wherein unauthenticated visitors could inject SQL statements into WordPress. SQL injection could allow an attacker to gain control of your site.
Severity: critical
Fixed in: no fix yet
Security risk: upload. A vulnerability exists wherein an unauthenticated user could upload a malicious file to the site. This could result in the disclosure of sensitive information or lead to complete site compromise.
Severity: critical
Fixed in: no fix yet
Security risk: privesc. It could be possible to elevate a user’s privileges to a higher permission level.
Severity: critical
Fixed in: no fix yet
Security risk: object injection. This is an application level vulnerability that could allow an attacker to perform different kinds of malicious attacks, such as Code Injection, SQL Injection, Path Traversal and Application Denial of Service, depending on the context. This could result in sensitive data disclosure or site compromise.
Severity: critical
Fixed in: no fix yet
Security risk: rfi. A File Inclusion vulnerability allows an attacker to include a file, usually exploiting a “dynamic file inclusion” mechanisms implemented in the target application. Remote File Inclusion is the process of including files from a remote source.
Severity: high
Fixed in: no fix yet
Security risk: xss. Data from an attacker could be interpreted as code by site visitors’ web browsers. The ability to run code in another site visitors’ browser can be abused to steal information, or modify site configuration.
Severity: medium
Fixed in: no fix yet
Security risk: no authorisation. An unknown vulnerability exists.
Severity: medium
Fixed in: no fix yet
2. WordPress Update Warning:
The WordPress update page is displaying a warning that my site will not receive updates for newer versions of WordPress.
Please look into this matter asap and If there are any additional details or actions required from my side, please let me know, I’ll be happy to assist.
Thank you