<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>WP-Hub · مرجع تخصصی وردپرس</title>
    <link>https://wp-hub.org/</link>
    <description>پایش بلادرنگ آسیب‌پذیری‌های CVE، راهنمای افزایش سرعت و بهینه‌سازی، هوش مصنوعی و تحلیل افزونه‌های وردپرس.</description>
    <language>fa-IR</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:41:18 +0000</lastBuildDate>
    <atom:link href="https://wp-hub.org/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>راهنمای جامع بهینه‌سازی سرعت وردپرس از صفر تا صد</title>
      <link>https://wp-hub.org/learn/wp-speed-optimization</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/wp-speed-optimization</guid>
      <description>سرعت لود یک وب‌سایت وردپرسی فقط یک امتیاز در ابزارهای تست سرعت نیست؛ مستقیماً روی نرخ تبدیل (Conversion Rate)، رتبه سئو در نتایج گوگل و تجربه کاربری کاربران اثر می‌گذارد. در این راهنما، بدون شعار و با روش‌های فنی اثبات‌شده، سایتت را سبک و فوق‌سریع کن.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>مقایسه بهترین افزونه‌های بهینه‌سازی سرعت و کش وردپرس</title>
      <link>https://wp-hub.org/learn/wp-performance-plugins</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/wp-performance-plugins</guid>
      <description>انتخاب افزونه کش مناسب برای وردپرس نباید بر اساس حدس و گمان یا تبلیغات باشد؛ بلکه کاملاً به نوع وب‌سرور هاست شما (LiteSpeed، Nginx یا Apache)، میزان پیچیدگی قالب و نوع وب‌سایت (وبلاگی یا ووکامرس) بستگی دارد. در این مقاله ۴ افزونه برتر سرعت وردپرس را با هم مقایسه می‌کنیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>راهنمای جامع انواع کش در وردپرس؛ از Page Cache تا Redis</title>
      <link>https://wp-hub.org/learn/wp-caching-guide</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/wp-caching-guide</guid>
      <description>کشینگ (Caching) یعنی ذخیره موقت نتایج محاسبات سنگین برای تحویل فوق‌سریع به درخواست‌های بعدی. در وردپرس بدون سیستم کش، هر بازدیدکننده باعث اجرای صدها کوئری PHP و SQL می‌شود که سرور را زیر بار سنگین خفه می‌کند. در این راهنما با انواع کش و بهترین روش پیکربندی آن آشنا می‌شوید.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>نسخه وصله‌شده (Patch) یعنی چه و چطور بفهمیم واقعاً رفع شده؟</title>
      <link>https://wp-hub.org/learn/what-is-patch</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/what-is-patch</guid>
      <description>وقتی در اخبار می‌شنویم که یک افزونه وردپرس آسیب‌پذیری داشته و حالا &quot;پچ&quot; شده، دقیقاً یعنی چه؟ آیا با زدن دکمه آپدیت، سایت ما کاملا امن میشه؟ در این مقاله مفهوم وصله امنیتی رو بررسی می‌کنیم و یاد می‌گیریم چطور از رفع شدن واقعی مشکلات مطمئن بشیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>CVSS چه چیزی را اندازه می‌گیرد؟</title>
      <link>https://wp-hub.org/learn/what-is-cvss</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/what-is-cvss</guid>
      <description>احتمالا تا حالا دیدی که در اخبار امنیتی می‌نویسن یک آسیب‌پذیری دارای امتیاز ۹.۸ از ۱۰ است! این نمره از کجا میاد و دقیقا چه معنی میده؟ در این مقاله با مفهوم CVSS آشنا میشیم و می‌بینیم چطور می‌تونه به ما در اولویت‌بندی رفع باگ‌های امنیتی کمک کنه.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>CVE چیست و چه چیزی را ثابت می‌کند؟</title>
      <link>https://wp-hub.org/learn/what-is-cve</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/what-is-cve</guid>
      <description>وقتی صحبت از امنیت سایت‌ها و سیستم‌های کامپیوتری میشه، همیشه یک اصطلاح خیلی تکرار میشه: CVE. اما CVE چیست و دقیقا چه کاربردی داره؟ در این مقاله می‌خواهیم به‌طور کامل به بررسی مفهوم CVE بپردازیم و ببینیم که چرا برای امنیت وردپرس و هر پلتفرم دیگه‌ای ضروریه.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>چطور دسترسی مدیران وردپرس را امن کنیم؟</title>
      <link>https://wp-hub.org/learn/secure-access</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/secure-access</guid>
      <description>بخش ورود (Login) سایت شما اولین هدف هکرها و ربات‌های مخرب است. اگر دسترسی مدیران سایت امن نباشد، تمام لایه‌های دیگر امنیتی بی‌معنی خواهند بود. در این مقاله به بررسی راهکارهای عملی برای امن‌سازی صفحه ورود و مدیریت کاربران می‌پردازیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>چک‌لیست بروزرسانی امن وردپرس (گام به گام)</title>
      <link>https://wp-hub.org/learn/safe-update</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/safe-update</guid>
      <description>بروزرسانی سایت‌های وردپرسی یکی از ضروری‌ترین اقدامات برای حفظ امنیت و کارایی است. اما آپدیت اشتباه می‌تواند به قیمت قطعی سایت و از دست رفتن اطلاعات تمام شود. در این مقاله چک‌لیست کاملی برای آپدیت امن وردپرس را بررسی می‌کنیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>چرا افزونه‌های قدیمی خطرناک‌اند؟</title>
      <link>https://wp-hub.org/learn/outdated-plugins</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/outdated-plugins</guid>
      <description>نگه داشتن یک افزونه قدیمی وردپرس در سایت مثل این است که درِ ورودی خانه‌تان را برای سارقان باز بگذارید. در این مقاله به بررسی خطرات افزونه‌های بدون آپدیت می‌پردازیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>بازبینی امنیت ماهانه وردپرس — ۷ بررسی کوتاه</title>
      <link>https://wp-hub.org/learn/monthly-security</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/monthly-security</guid>
      <description>حفظ امنیت یک سایت وردپرسی یک کار مقطعی نیست، بلکه فرآیندی مستمر است. با انجام این ۷ بررسی کوتاه به صورت ماهانه، ریسک هک شدن سایتت رو به حداقل برسون.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>CVSS را چطور بخوانیم؟ راهنمای کامل امتیازدهی آسیب‌پذیری</title>
      <link>https://wp-hub.org/learn/cvss-guide</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/cvss-guide</guid>
      <description>وقتی یک آسیب‌پذیری وردپرس منتشر می‌شود، معمولاً یک عدد و دسته‌بندی شدت (مثل ۹.۸ بحرانی) به همراه آن اعلام می‌شود. در این مقاله می‌فهمیم CVSS چیست و چطور باید این امتیازات را درک کنیم.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>بعد از انتشار یک CVE چه کار باید کرد؟</title>
      <link>https://wp-hub.org/learn/cve-response</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/cve-response</guid>
      <description>در دنیای امنیت وردپرس، انتشار یک CVE به معنای اعلام رسمی یک آسیب‌پذیری است. در این مقاله یاد می‌گیریم که دقیقاً بعد از شنیدن خبر یک باگ امنیتی، چه قدم‌هایی را باید برداریم تا سایت ما هک نشود.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>۱۰ کار فوری بعد از مشاهده CVE بحرانی</title>
      <link>https://wp-hub.org/learn/critical-cve-checklist</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/critical-cve-checklist</guid>
      <description>وقتی یک آسیب‌پذیری با درجه اهمیت بحرانی (Critical CVE) برای یکی از افزونه‌ها یا قالب‌های سایتت منتشر می‌شه، دقیقه‌ها مهم هستن. این چک‌لیست به تو کمک می‌کنه تا بدون استرس و به‌صورت سیستماتیک، خطر رو مهار کنی.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>راهنمای جامع Core Web Vitals در وردپرس؛ بهبود LCP، INP و CLS</title>
      <link>https://wp-hub.org/learn/core-web-vitals</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/core-web-vitals</guid>
      <description>شاخص‌های حیاتی وب یا Core Web Vitals معیارهای استاندارد گوگل برای سنجش سرعت واقعی، پایداری بصری و پاسخگویی به تعاملات کاربر هستند. سبز شدن این شاخص‌ها در سرچ کنسول گوگل مستقیماً رتبه ارگانیک شما را ارتقا می‌دهد. در این راهنما با نحوه عیب‌یابی و رفع آنها در وردپرس آشنا می‌شوید.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>۵ بررسی امنیتی قبل از تحویل سایت وردپرسی به مشتری</title>
      <link>https://wp-hub.org/learn/client-handoff</link>
      <guid isPermaLink="true">https://wp-hub.org/learn/client-handoff</guid>
      <description>طراحی سایت تمام شده و وقت تحویل پروژه‌ست؟ قبل از اینکه کلید سایت رو به مشتری بدی، این ۵ قدم امنیتی رو حتماً اجرا کن تا هم اعتبار خودت حفظ بشه و هم سایت مشتری در امان بمونه.</description>
      <pubDate>Wed, 26 Aug 2026 16:21:40 +0000</pubDate>
      <category>آموزش وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5269</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5269</guid>
      <description>The Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.5. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 15:05:34 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اشیاء PHP (Object Injection) در افزونه Sunshine Photo Cart – Client Photo Gallery &amp; Photo Proofing for Photographers (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5268</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5268</guid>
      <description>The Sunshine Photo Cart – Client Photo Gallery &amp; Photo Proofing for Photographers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.1. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with custom role-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</description>
      <pubDate>Sat, 03 Oct 2026 18:39:42 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Premmerce Wishlist for WooCommerce (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5267</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5267</guid>
      <description>The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.13. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Thu, 01 Oct 2026 11:59:41 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Social Rocket – Social Sharing Plugin (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5266</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5266</guid>
      <description>The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.5. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 16:14:17 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Mapster WP Maps (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5265</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5265</guid>
      <description>The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 11:27:01 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه Radius Booking – Appointment Booking Calendar &amp; Scheduling for Services &amp; Events (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5264</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5264</guid>
      <description>The Radius Booking – Appointment Booking Calendar &amp; Scheduling for Services &amp; Events plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.19. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Mon, 05 Oct 2026 16:24:39 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] جعل درخواست سمت سرور (SSRF) در افزونه PDF Smart Viewer for Elementor (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5263</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5263</guid>
      <description>افزونه PDF Smart Viewer for Elementor تا نسخه 1.0.4 دچار آسیب‌پذیری جعل درخواست سمت سرور (SSRF) است. این نقص امنیتی به مهاجمان احرازویت‌نشده اجازه می‌دهد تا درخواست‌های وب دلخواهی را از طریق سرور میزبان ارسال کرده و به اطلاعات سرویس‌های داخلی دسترسی پیدا کنند یا آن‌ها را تغییر دهند. از آنجا که این افزونه تاکنون فاقد وصله امنیتی رسمی است، اکیداً توصیه می‌شود تا زمان انتشار به‌روزرسانی، افزونه را غیرفعال کرده یا از یک فایروال وب (WAF) برای مسدودسازی درخواست‌های مخرب استفاده کنید.</description>
      <pubDate>Sun, 04 Oct 2026 08:24:54 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5262</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5262</guid>
      <description>The WPFunnels – Funnel Builder for WooCommerce with Checkout &amp; One Click Upsell plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.13.1. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Wed, 30 Sep 2026 11:23:32 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile &amp; User signup (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5261</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5261</guid>
      <description>The ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile &amp; User signup plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.8. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Mon, 05 Oct 2026 16:14:05 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه VikRentCar Car Rental Management System (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5260</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5260</guid>
      <description>The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4.7. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 16:36:53 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Database for CF7 (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5259</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5259</guid>
      <description>The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.6. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 13:22:36 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه Gmedia Photo Gallery (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5258</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5258</guid>
      <description>The Gmedia Photo Gallery plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.25.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Mon, 05 Oct 2026 16:41:56 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[CRITICAL] آپلود فایل غیرمجاز بدون احراز هویت (File Upload) در قالب Doctreat - Hospitals and Doctors Directory WordPress Listing Theme (CVSS 9.8)</title>
      <link>https://wp-hub.org/vulnerabilities/5257</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5257</guid>
      <description>The Doctreat - Hospitals and Doctors Directory WordPress Listing Theme theme for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.0. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site&#x27;s server, which may make remote code execution possible.</description>
      <pubDate>Mon, 05 Oct 2026 16:33:10 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Unlimited Elements for Elementor (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5256</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5256</guid>
      <description>The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.19. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Fri, 02 Oct 2026 07:04:18 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Video Background Block – Add Stunning Video Backgrounds to Any Section (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5255</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5255</guid>
      <description>The Video Background Block – Add Stunning Video Backgrounds to Any Section plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.3. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 16:21:05 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Photonic Gallery &amp; Lightbox for Flickr, SmugMug &amp; Others (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5254</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5254</guid>
      <description>The Photonic Gallery &amp; Lightbox for Flickr, SmugMug &amp; Others plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.36. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Wed, 30 Sep 2026 13:34:47 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] ارتقای سطح دسترسی (Privilege Escalation) در افزونه Meta Box AIO (CVSS 7.3)</title>
      <link>https://wp-hub.org/vulnerabilities/5253</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5253</guid>
      <description>The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.7.1. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intended for their role.</description>
      <pubDate>Mon, 05 Oct 2026 15:04:48 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5252</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5252</guid>
      <description>The WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 16:20:25 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه Newsletter Subscription Form – User Subscriptions Form, Capture Email (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5251</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5251</guid>
      <description>The Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.5.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Mon, 05 Oct 2026 15:30:57 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] اجرای کد از راه دور (RCE) در افزونه WP Coder – Insert &amp; Manage Code Snippets (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5250</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5250</guid>
      <description>The Coder plugin for WordPress is vulnerable to Remote Code Execution in versions 4.0 through 4.5.1. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with editor-level access and above, to execute arbitrary code on the server.</description>
      <pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اسکریپت ذخیره‌شده (Stored XSS) در افزونه Product Designer for WooCommerce WordPress | Lumise (CVSS 7.2)</title>
      <link>https://wp-hub.org/vulnerabilities/5249</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5249</guid>
      <description>The Product Designer for WooCommerce WordPress | Lumise plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.1. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</description>
      <pubDate>Mon, 05 Oct 2026 12:31:53 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[MEDIUM] اجرای کدهای دلخواه (Code Execution) در افزونه All in One SEO – AI SEO Plugin to Boost SEO Rankings &amp; Traffic (Schema, Local SEO, Sitemap &amp; SEO Insights) (CVSS 6.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5248</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5248</guid>
      <description>The All in One SEO plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 5.0.2.0. This is due to the use of do_shortcode() on user supplied input. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes registered on the site. The impact depends on which shortcodes the site has registered, so a site running a plugin whose shortcodes expose data or perform actions is affected more severely.</description>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه WP Data Access – App Builder for Tables, Forms, Dashboards, Charts &amp; Maps (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5247</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5247</guid>
      <description>The WP Data Access – App Builder for Tables, Forms, Dashboards, Charts &amp; Maps plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.5.82. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Fri, 02 Oct 2026 09:04:58 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق اشیاء PHP (Object Injection) در افزونه WPBot – ChatBot Conversational Forms (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5246</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5246</guid>
      <description>The WPBot – ChatBot Conversational Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.0. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</description>
      <pubDate>Tue, 29 Sep 2026 09:44:55 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
    <item>
      <title>[HIGH] تزریق کدهای SQL (SQLi) در افزونه SendPress Newsletters (CVSS 7.5)</title>
      <link>https://wp-hub.org/vulnerabilities/5245</link>
      <guid isPermaLink="true">https://wp-hub.org/vulnerabilities/5245</guid>
      <description>The SendPress Newsletters plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.26.1.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</description>
      <pubDate>Mon, 05 Oct 2026 16:53:05 +0000</pubDate>
      <category>امنیت وردپرس</category>
    </item>
  </channel>
</rss>