
Elementor CSRF Flaw Puts WordPress Hosts on Update Alert
Patchstack says Elementor 4.3.0 and 4.3.1 allowed crafted links to bypass REST API CSRF checks, raising the risk of unwanted administrator actions on WordPress sites.
Sharp briefings on web hosting, internet domains, cloud infrastructure and the fragile plumbing of being online.

Patchstack says Elementor 4.3.0 and 4.3.1 allowed crafted links to bypass REST API CSRF checks, raising the risk of unwanted administrator actions on WordPress sites.

Cloudflare says it has fixed a cross-tenant data exposure vulnerability in Cloudflare Containers and Cloudflare Sandboxes after outside researchers showed that a new workload could recover residual disk […]

WordPress site operators have another core update to prioritize after researchers disclosed technical details and a proof-of-concept for a vulnerability dubbed Click2Shell. BleepingComputer reports that the issue is […]

Hostinger says a LiteSpeed Web Server zero-day was used against one Brazil shared-hosting server, with LSWS 6.3.7 Build 2 deployed across its fleet the same day.

Acronis says limited in-the-wild exploitation has targeted its cPanel backup plugin; patched builds are available for both cPanel & WHM and Plesk integrations.

A new mass-scanning campaign is targeting Vite development servers that have been left reachable from the public internet, with attackers attempting to collect cloud credentials and configuration data […]

Cloudflare is using its 1.1.1.1 resolver to test ML-DSA-44 DNSSEC validation at Internet scale, surfacing size and downgrade issues DNS operators will need to solve before a wider post-quantum migration.

Cloudflare Automatic Key Exchange measures origin TLS support and prefers post-quantum key exchange where available, reducing handshake retries for eligible hosted sites.

Microsoft will raise the minimum Exchange Server 2016/2019 baseline for hybrid mail into Exchange Online, creating delivery risk for unpatched servers.

A reported BGP hijacking incident was used to push a malicious update to Virtualizor, a virtualization control panel used by hosting providers and VPS operators, according to BleepingComputer. […]