Google Quietly Raised Ad Prices, Court Orders More Transparency via @sejournal, @MattGSouthern

Google raised ad prices incrementally through internal “pricing knobs” that advertisers couldn’t detect, according to federal court documents.

  • Google raised ad prices 5-15% at a time using “pricing knobs” that made increases look like normal auction fluctuations.
  • Google’s surveys showed advertisers noticed higher costs but didn’t realize Google was causing the increases.
  • A federal judge now requires Google to publicly disclose auction changes that could raise advertiser costs.

https://www.searchenginejournal.com/google-quietly-raised-ad-prices-court-orders-more-transparency/555190/




Hexstrike AI, nuovo tool di OffSec, è già stato preso di mira dal cybercrimine


Appena rilasciato e già preso di mira dagli attaccanti: Hexstrike AI, un nuovo tool di offensive security (OffSec), è già entrato nelle mani dei cybercriminali che lo stanno usando per cercare di sfruttare diverse vulnerabilità.

Come si legge sul sito ufficiale dello strumento, Hexstrike AI è stato pensato per essere “un framework rivoluzionario di sicurezza offensiva basato sull’intelligenza artificiale che combina strumenti di sicurezza professionali con agenti autonomi di intelligenza artificiale per fornire funzionalità complete di test di sicurezza“.

Come riporta un recente report di CheckPoint, però, poche ore dopo il rilascio del tool i cybercriminali hanno cominciato a valutare come usare il framework per sfruttare le vulnerabilità zero-day di Citrix NetScaler ADC e Gateway, rese note lo scorso 26 agosto. Insomma, un tool che dovrebbe proteggere dagli attacchi può diventare potenzialmente una minaccia a sua volta, un potente strumento al servizio del cybercrimine.

HexStrike AI Credits: CheckPoint

Sui forum del dark web si discute su come usare Hexstrike AI a proprio vantaggio. Credits: CheckPoint

E in effetti Hexstrike AI promette di essere un tool molto potente: lo strumento infatti introduce un livello di astrazione e orchestrazione per far eseguire autonomamente tool di sicurezza a modelli di IA quali Claude, GPT e Copilot. Grazie agli MCP Agent, Hexstrike AI consente di eseguire in contemporanea e senza intervento umano oltre 150 tool di sicurezza.

Come sottolinea CheckPoint, il tempismo tra la scoperta delle vulnerabilità Citrix e il rilascio del tool di IA è preoccupante: gli attaccanti potrebbero agire molto più in fretta del normale e sfruttare i bug prima che le organizzazioni possano agire. “Sfruttare queste vulnerabilità non è banale. Gli attaccanti devono comprendere le operazioni di memoria, i bypass di autenticazione e le peculiarità dell’architettura di NetScaler. Storicamente, questo tipo di lavoro ha richiesto tecnici altamente qualificati e settimane di sviluppo. Con Hexstrike AI, questa barriera sembra essere crollata” evidenzia CheckPoint.

Tutte le implicazioni positive del tool, come gli aenti intelligenti che scansionano migliaia di IP simultaneamente e le attività che possono essere inizializzate ed eseguite in pochi minuti invece che in ore o giorni, hanno anche la controparte negativa quando vengono sfruttate dai cybercriminali.

La soluzione, in questo momento, è applicare immediatamente le patch risolutive e investire su strumenti di protezione all’avanguardia, in grado di contrastare la capacità di adattamento degli attaccanti.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/03/hexstrike-ai-nuovo-tool-di-offsec-e-gia-stato-preso-di-mira-dal-cybercrimine/?utm_source=rss&utm_medium=rss&utm_campaign=hexstrike-ai-nuovo-tool-di-offsec-e-gia-stato-preso-di-mira-dal-cybercrimine




Interaction To Next Paint: 9 Content Management Systems Ranked via @sejournal, @martinibuster

Interaction to Next Paint (INP) is a meaningful Core Web Vitals metric because it represents how quickly a web page responds to user input. It is so important that the HTTPArchive has a comparison of INP across content management systems. The following are the top content management systems ranked by Interaction to Next Paint.

What Is Interaction To Next Paint (INP)?

INP measures how responsive a web page is to user interactions during a visit. Specifically, it measures interaction latency, which is the time between when a user clicks, taps, or presses a key and when the page visually responds.

This is a more accurate measurement of responsiveness than the older metric it replaced, First Input Delay (FID), which only captured the first interaction. INP is more comprehensive because it evaluates all clicks, taps, and key presses on a page and then reports a representative value based on the longest meaningful latency.

The INP score is representative of the page’s responsive performance. For that reason**,** extreme outliers are filtered out of the calculation so that the score reflects typical worst-case responsiveness.

Web pages with poor INP scores create a frustrating user experience that increases the risk of page abandonment. Fast responsiveness enables a smoother experience that supports higher engagement and conversions.

INP Scores Have Three Ratings:

  • Good: Below or at 200 milliseconds
  • Needs Improvement: Above 200 milliseconds and below or at 500 milliseconds
  • Poor: Above 500 milliseconds

Related: Get Ready For Google’s INP Metric With These 5 Tools

Content Management System INP Champions

The latest Interaction to Next Paint (INP) data shows that all major content management systems improved from June to July, but only by incremental improvements.

Joomla posted the largest gain with a 1.12% increase in sites achieving a good score. WordPress followed with a 0.88% increase in the number of sites posting a good score, while Wix and Drupal improved by 0.70% and 0.64%.

Duda and Squarespace also improved, though by smaller margins of 0.46% and 0.22%. Even small percentage changes can reflect real improvements in how users experience responsiveness on these platforms, so it’s encouraging that every publishing platform in this comparison is improving.

CMS INP Ranking By Monthly Improvement

  1. Joomla: +1.12%
  2. WordPress: +0.88%
  3. Wix: +0.70%
  4. Drupal: +0.64%
  5. Duda: +0.46%
  6. Squarespace: +0.22%

Which CMS Has The Best INP Scores?

Month-to-month improvement shows who is doing better, but that’s not the same as which CMS is doing the best. The July INP results show a different ranking order of content management systems when viewed by overall INP scores.

Squarespace leads with 96.07% of sites achieving a good INP score, followed by Duda at 93.81%. This is a big difference from the Core Web Vitals rankings, where Duda is consistently ranked number one. When it comes to arguably the most important Core Web Vital metric, Squarespace takes the lead as the number one ranked CMS for Interaction to Next Paint.

Wix and WordPress are ranked in the middle with 87.52% and 86.77% of sites showing a good INP score, while Drupal, with a score of 86.14%, is ranked in fifth place, just a fraction behind WordPress.

Ranking in sixth place in this comparison is Joomla, trailing the other five with a score of 84.47%. That score is not so bad considering that it’s only two to three percent behind Wix and WordPress.

CMS INP Rankings for July 2025

  1. Squarespace – 96.07%
  2. Duda: 93.81%
  3. Wix: 87.52%
  4. WordPress: 86.77%
  5. Drupal: 86.14%
  6. Joomla: 84.47%

These rankings show that even platforms that lag in INP performance, like Joomla, are still improving, and it could be that Joomla’s performance may best the other platforms in the future if it keeps up its improvement.

In contrast, Squarespace, which already performs well, posted the smallest gain. This indicates that performance improvement is uneven, with systems advancing at different speeds. Nevertheless, the latest Interaction to Next Paint (INP) data shows that all six content management systems in this comparison improved from June to July. That upward performance trend is a positive sign for publishers.

What About Shopify’s INP Performance?

Shopify has strong Core Web Vitals performance, but how well does it compare to these six content management systems? This might seem like an unfair comparison because shopping platforms require features, images, and videos that can slow a page down. But Duda, Squarespace, and Wix offer ecommerce solutions, so it’s actually a fair and reasonable comparison.

We see that the rankings change when Shopify is added to the INP comparison:

Shopify Versus Everyone

  1. Squarespace: 96.07%
  2. Duda: 93.81%
  3. Shopify: 89.58%
  4. Wix: 87.52%
  5. WordPress: 86.77%
  6. Drupal: 86.14%
  7. Joomla: 84.47%

Shopify is ranked number three. Now look at what happens when we compare the three shopping platforms against each other:

Top Ranked Shopping Platforms By INP

  1. BigCommerce: 95.29%
  2. Shopify: 89.58%
  3. WooCommerce: 87.99%

BigCommerce is the number-one-ranked shopping platform for the important INP metric among the three in this comparison.

Lastly, we compare the INP performance scores for all the platforms together, leading to a surprising comparison.

CMS And Shopping Platforms Comparison

  1. Squarespace: 96.07%
  2. BigCommerce: 95.29%
  3. Duda: 93.81%
  4. Shopify: 89.58%
  5. WooCommerce: 87.99%
  6. Wix: 87.52%
  7. WordPress: 86.77%
  8. Drupal: 86.14%
  9. Joomla: 84.47%

All three ecommerce platforms feature in the top five rankings of content management systems, which is remarkable because of the resource-intensive demands of ecommerce websites. WooCommerce, a WordPress-based shopping platform, ranks in position five, but it’s so close to Wix that they are virtually tied for position five.

Takeaways

INP measures the responsiveness of a web page, making it a meaningful indicator of user experience. The latest data shows that while every CMS is improving, Squarespace, BigCommerce, and Duda outperform all other content platforms in this comparison by meaningful margins.

All of the platforms in this comparison show high percentages of good INP scores. The number four-ranked Shopify is only 6.49 percentage points behind the top-ranked Squarespace, and 84.47% of the sites published with the bottom-ranked Joomla show a good INP score. These results show that all platforms are delivering a quality experience for users

View the results here (must be logged into a Google account to view).

Featured Image by Shutterstock/Roman Samborskyi

https://www.searchenginejournal.com/interaction-to-next-paint-9-content-management-systems-ranked/555090/




Google Avoids Breakup As Judge Bars Exclusive Default Search Deals via @sejournal, @MattGSouthern

A federal judge outlined remedies in the U.S. search antitrust case that bar Google from using exclusive default search deals but stop short of forcing a breakup.

Reuters reports that Google won’t have to divest Chrome or Android, but it may have to share some search data with competitors under court-approved terms.

Google says it will appeal.

What The Judge Ordered

Judge Amit P. Mehta barred Google from entering or maintaining exclusive agreements that tie the distribution of Search, Chrome, Google Assistant, or the Gemini app to other apps, licenses, or revenue-share arrangements.

The ruling allows Google to continue paying for placement but prohibits exclusivity that could block rivals.

The order also envisions Google making certain search and search-ad syndication services available to competitors at standard rates, alongside limited data sharing for “qualified competitors.”

Mehta ordered Google to share some search data with competitors under specific protections to help them improve their relevance and revenue. Google argued this could expose its trade secrets and plans to appeal the decision.

The judge directed the parties to meet and submit a revised final judgment by September 10. Once entered, the remedies would take effect 60 days later, run for six years, and be overseen by a technical committee. Final language could change based on the parties’ filing.

How We Got Here

In August 2024, Mehta found Google illegally maintained a monopoly in general search and related text ads.

Judge Amit P. Mehta wrote in his August 2024 opinion:

“Google is a monopolist, and it has acted as one to maintain its monopoly.”

This decision established the need for remedies. Today’s order focuses on distribution and data access, rather than breaking up the company.

What’s Going To Change

Ending exclusivity changes how contracts for default placements can be made across devices and browsers. Phone makers and carriers may need to update their agreements to follow the new rules.

However, the ruling doesn’t require any specific user experience change, like a choice screen. The results will depend on how new contracts are created and approved by the court.

Next Steps

Expect a gradual rollout if the final judgment follows today’s outline.

Here are the next steps to watch for:

  • The revised judgment that the parties will submit by September 10.
  • Changes to contracts between Google and distribution partners to meet the non-exclusivity requirement.
  • Any pilot programs or rules that specify who qualifies as a “qualified competitor” and what data they can access.

Separately, Google faces a remedies trial in the ad-tech case in late September. This trial could lead to changes that affect advertising and measurement.

Looking Ahead

If the parties submit a revised judgment by September 10, changes could start about 60 days after the court’s final order. This might shift if Google gets temporary relief during an appeal.

In the short term, expect contract changes rather than product updates.

The final judgment will determine who can access data and which types are included. If the program is limited, it may not significantly affect competition. If broader, competitors might enhance their relevance and profit over the six-year period.

Also watch the ad tech remedies trial this month. Its results, along with the search remedies, will shape how Google handles search and ads in the coming years.

https://www.searchenginejournal.com/google-avoids-breakup-as-judge-bars-exclusive-default-search-deals/555080/




Il data breach contro Salesloft impatta centinaia di servizi


Lo scorso 20 agosto Salesloft aveva avvertito di un incidente di sicurezza che ha colpito Drift, il proprio chatbot di IA usato per convertire le interazioni utente in lead di Salesforce. Gli attaccanti sono riusciti a entrare in possesso di token Drift OAuth per accedere a istanze di Salesforce e sottrarre grandi volumi di dati. 

“L’autore dell’attacco ha esportato sistematicamente grandi volumi di dati da numerose istanze aziendali di Salesforce. GTIG ritiene che l’obiettivo principale dell’autore dell’attacco fosse quello di raccogliere credenziali. Dopo aver sottratto i dati, il gruppo ha cercato tra i dati informazioni riservate che potessero essere potenzialmente utilizzate per compromettere gli ambienti delle vittime” ha spiegato Google Threat Intelligence Group in un report.

Salesloft

La campagna, iniziata l’8 agosto e durata almeno fino al 18 agosto, sarebbe a opera del gruppo UNC6395. Se inizialmente sembrava che il pericolo fosse limitato solo a quei clienti che integrano Drift in Salesforce, gli ultimi aggiornamenti di Google avvertono che la campagna impatta anche su altre integrazioni. “Consigliamo ora a tutti i clienti Salesloft Drift di considerare tutti i token memorizzati o connessi alla piattaforma Drift come potenzialmente compromessi” si legge nel report aggiornato.

Come si legge su un articolo di Krebs On Security, questo significa che potenzialmente gli hacker hanno sottratto token d’autenticazione per centinaia di servizi che si possono integrare con la piattaforma, inclusi Slack, Google Workspace, Amazon S3, Azure e OpenAI.

Per quanto riguarda i suoi servizi, Google ha revocato i token compromessi degli utenti impattati e ha temporaneamente disabilitato l’integrazione tra Workspace e Drift. La compagnia ha invitato inoltre tutti i clienti di Salesloft Drift che integrano la piattaforma a revocare e ruotare le credenziali per le applicazioni connesse.

Nell’ultima comunicazione, Salesloft ha specificato di aver ingaggiato Mandiant e Coalition per analizzare e gestire l’incidente. “Consigliamo a tutti i clienti Drift che gestiscono le proprie connessioni Drift ad applicazioni di terze parti tramite chiave API di revocare in modo proattivo la chiave esistente e riconnettersi utilizzando una nuova chiave API per queste applicazioni. Ciò riguarda solo le integrazioni Drift basate su chiave API. Le applicazioni OAuth vengono gestite direttamente da Salesloft” ha dichiarato la compagnia.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/02/il-data-breach-contro-salesloft-impatta-centinaia-di-servizi/?utm_source=rss&utm_medium=rss&utm_campaign=il-data-breach-contro-salesloft-impatta-centinaia-di-servizi




Velociraptor, tool per l’analisi forense digitale, è stato sfruttato per l’accesso remoto


Qualche giorno fa la Counter Threat Unit di Sophos ha scoperto che Velociraptor, un tool per l’analisi forense digitale e la risposta agli incidenti di sicurezza, è stato sfruttato per ottenere l’accesso remoto a una rete aziendale.

Secondo il team, gli attaccanti hanno usato il software per scaricare ed eseguire Visual Studio Code con l’obiettivo di creare un canale di comunicazione con un server C2.

Nel dettaglio, gli attaccanti hanno usato msiexec di Windows per scaricare un installer da un dominio Cloudflare Workers, una cartella di staging contenente diversi tool per gli attacchi. Il file ha installato Velociraptor, il quale ha permesso agli attaccanti di scaricare Visual Studio Code dalla stessa cartella di staging in modo da eseguire codice da remoto. Secondo quanto riportato dai ricercatori di Sophos, i cybercriminali hanno usato msiexec per scaricare e installare altri payload malevoli.

Velociraptor. Credits: Sophos

Velociraptor usato per creare un canale di comunicazione sfruttando Visual Studio Code. Credits: Sophos

L’attività sospetta di Visual Studio Code ha scatenato un alert che ha permesso al team di Sophos di agire tempestivamente e bloccare l’attacco del gruppo, isolando l’host colpito prima che gli attaccanti raggiungessero il loro vero scopo. Secondo la Counter Threat Unit, è molto probabile che il gruppo volesse distribuire un ransomware. 

“Gli attaccanti spesso abusano degli strumenti di monitoraggio e gestione remota (RMM). In alcuni casi, sfruttano strumenti preesistenti sui sistemi presi di mira. In altri, implementano gli strumenti durante l’attacco. L’incidente Velociraptor rivela che gli attaccanti stanno passando all’uso di strumenti di risposta agli incidenti per ottenere persistenza nelle reti e ridurre al minimo la quantità di malware che distribuiscono” ha spiegato il team di Sophos.

Per ridurre il rischio di questo tipo di attacchi e prevenire la minaccia ransomware, i ricercatori della compagnia consigliano di implementare un sistema EDR, monitorare attentamente l’uso dei tool ed eventuali attività sospette, effettuare backup regolari e, in generale, seguire le best practice note per garantire la sicurezza dei sistemi.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/09/01/velociraptor-tool-per-lanalisi-forense-digitale-e-stato-sfruttato-per-laccesso-remoto/?utm_source=rss&utm_medium=rss&utm_campaign=velociraptor-tool-per-lanalisi-forense-digitale-e-stato-sfruttato-per-laccesso-remoto




Google: AI Mode Sees “Big Improvements” On STEM Queries via @sejournal, @MattGSouthern

Google says AI Mode now handles complex STEM questions better and surfaces key details sooner, timed for back to school.

  • Google rolled out an iterative update to AI Mode
  • AI Mode now handles complex STEM questions and delivers more concise responses.
  • The update arrives as students return to school.

https://www.searchenginejournal.com/google-ai-mode-sees-big-improvements-on-stem-queries/554985/




How to Use Google Ads Performance Max Channel Reporting via @sejournal, @brookeosmundson

For years, marketers have asked for better visibility into how individual channels contribute to Performance Max results.

Google has released a tutorial walking advertisers through its new Performance Max channel reporting. This reporting feature offers more transparency into how campaigns perform across Search, YouTube, Display, Gmail, Discover, and Maps.

With this new report, you can now dig deeper into performance by channel and format, making it easier to analyze results and troubleshoot.

Here’s a look at how to find the report and what you can do with it.

Where to Find Channel Performance Reporting

To find and access the channel reporting, head to your Google Ads account.

From there, navigate to: Campaign >> Insights & Reports >> Channel Performance

google ads performance max channel reportingImage credit: Google, April 2025

Once you’re there, you’ll see these items:

  • A performance summary overview
  • A channel-to-goals visualization
  • Channel distribution table.

These items provide more than just a static view of performance. You’re able to click on specific channels to drill down into related reports, like placements on the Google Display Network, or Search Terms from the Search channel.

Exploring the Reports and Visualizations

The channel performance page isn’t just a high-level dashboard. It provides several views and reports that give you more context on how your ads are performing across Google’s network. Here’s a closer look at the most useful areas:

Ad Format Views

Not every ad performs the same across channels, which is why Google lets you break results down by ad format.

For example, you can see how video ads perform on YouTube compared to product ads shown on Search. This helps you spot whether one creative type is pulling more weight and whether you need to adjust your creative mix or budgets to support higher-performing formats.

Product-Driven Insights

If you’re running Shopping or retail campaigns, this section shows how ads tied to product data perform across channels.

You can see Shopping ads on Search as well as dynamic remarketing ads on Display. This gives ecommerce advertisers a clearer picture of how product feeds contribute to results beyond just one channel.

Channel Distribution Table

This table is one of the most detailed reports in the new view. It includes impressions, clicks, interactions, conversions, conversion value, and cost, all broken down by channel.

You can customize the table to highlight the metrics that matter most to your goals, such as ROAS or CPA, and even segment results by ad format (like video versus product ads).

Since the table is downloadable, you can also share it with teams or clients for transparent reporting.

Status Column and Diagnostics

The status column acts as a built-in troubleshooting tool. It surfaces issues or recommendations related to specific channels or formats, such as diagnostic warnings if ads aren’t serving as expected.

By reviewing these, you can quickly identify where performance may be limited and take action to resolve issues before they affect results at scale.

Reviewing Single-Channel vs. Cross-Channel CPA

One important takeaway from Google’s tutorial is that looking at average CPA or ROAS for a single channel doesn’t tell the full story.

Performance Max uses marginal ROI optimization, bidding in real time for the most cost-efficient conversions across all channels.

Since users don’t interact with just one channel, this cross-channel view helps advertisers see the broader picture of how campaigns drive results.

That means when evaluating effectiveness, Google recommends to prioritize your goals and audiences over individual channel performance.

How Advertisers Can Benefit From Performance Max Channel Reporting

The new reporting doesn’t change how Performance Max works behind the scenes, but it does help you:

  • Understand which channels support your goals most effectively
  • Identify areas where specific ad formats or channels may need creative or budget adjustments
  • Communicate results more clearly with stakeholders by showing cross-channel contributions

With Search Partner Network reporting coming in the future, Google is signaling a continued investment in giving advertisers deeper visibility.

Performance Max remains a cross-channel campaign type, but channel reporting is a welcome step toward transparency. By digging into these reports, advertisers can better understand how ads perform across Google properties and make smarter optimization decisions.

https://www.searchenginejournal.com/how-to-use-google-ads-performance-max-channel-reporting/554944/




Google Adds Guidance On JavaScript Paywalls And SEO via @sejournal, @martinibuster

Google is apparently having trouble identifying paywalled content due to a standard way paywalled content is handled by publishers like news sites. It’s asking that publishers with paywalled content change the way they block content so as to help Google out.

Search Related JavaScript Problems

Google updated their guidelines with a call for publishers to consider changing how they block users from paywalled content. It’s fairly common for publishers to use a script to block non-paying users with an interstitial although the full content is still there in the code. This may be causing issues for Google in properly identifying paywalled content.

A recent addition to their search documentation about JavaScript issues related to search they wrote:

“If you’re using a JavaScript-based paywall, consider the implementation.

Some JavaScript paywall solutions include the full content in the server response, then use JavaScript to hide it until subscription status is confirmed. This isn’t a reliable way to limit access to the content. Make sure your paywall only provides the full content once the subscription status is confirmed.”

The documentation doesn’t say what problems Google itself is having, but a changelog documenting the change offers more context about why they are asking for this change:

“Adding guidance for JavaScript-based paywalls

What: Added new guidance on JavaScript-based paywall considerations.

Why: To help sites understand challenges with the JavaScript-based paywall design pattern, as it makes it difficult for Google to automatically determine which content is paywalled and which isn’t.”

The changelog makes it clear that the way some publishers use JavaScript for blocking paywalled content is making it difficult for Google to know if the content is or is not paywalled.

The change was an addition to a numbered list of JavaScript problems publishers should be aware of, item number 10 on their “Fix Search-related JavaScript Problems” page.

Featured Image by Shutterstock/Kues

https://www.searchenginejournal.com/google-adds-new-guidance-on-javascript-paywalls-and-seo/554918/




TablePress WordPress Plugin Vulnerability Affects 700,000+ Sites via @sejournal, @martinibuster

A vulnerability in the TablePress WordPress plugin enables attackers to inject malicious scripts that run when someone visits a compromised page. It affects all versions up to and including version 3.2.

TablePress WordPress plugin

The TablePress plugin is used on more than 700,000 websites. It enables users to create and manage tables with interactive features like sorting, pagination, and search.

What Caused The Vulnerability

The problem came from missing input sanitization and output escaping in how the plugin handled the shortcode_debug parameter. These are basic security steps that protect sites from harmful input and unsafe output.

The Wordfence advisory explains:

“The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping.”

Input Sanitization

Input sanitization filters what users type into forms or fields. It blocks harmful input, like malicious scripts. TablePress didn’t fully apply this security step.

Output Escaping

Output escaping is similar, but it works in the opposite direction, filtering what gets output onto the website. Output escaping prevents the website from publishing characters that can be interpreted by browsers as code.

That’s exactly what can happen with TablePress because it has insufficient input sanitization , which enables an attacker to upload a script , and insufficient escaping to prevent the website from injecting malicious scripts into the live website. That’s what enables the stored cross-site scripting (XSS) attacks.

Because both protections were missing, someone with Contributor-level access or higher could upload a script that gets stored and runs whenever the page is visited. The fact that a Contributor-level authorization is necessary mitigates the potential for an attack to a certain extent.

Plugin users are recommended to update the plugin to version 3.2.1 or higher.

Featured Image by Shutterstock/Nithid

https://www.searchenginejournal.com/tablepress-wordpress-plugin-vulnerability-affects-700000-sites/554909/