Defending Your Digital Rights

    A non-profit organization committed to protecting digital freedoms, privacy, and security for vulnerable communities worldwide.

    About Us

    We are a collective of digital rights advocates, security experts, and educators committed to empowering individuals and communities with the knowledge and tools to protect their digital freedoms.

    Our Initiatives

    How we work to protect digital rights and empower communities

    Awareness

    Raising awareness about digital rights, privacy threats, and security best practices.

    Advocacy

    Advocating for policies and regulations that protect digital rights and freedoms.

    Education

    Providing training and resources on digital security for vulnerable groups.

    Support

    Offering direct assistance to individuals and organizations facing digital threats.

    Community Building

    Creating networks of digital rights defenders to share knowledge and resources.

    Collaboration

    Working with partners globally to develop solutions to digital security challenges.

    Security Alerts

    Latest WordPress security vulnerabilities affecting plugins, themes, and core.

    MEDIUM (5.8)
    Plugin

    Stored Cross-Site Scripting Vulnerability in NextMove Lite Plugin for WordPress

    Published Date: May 2, 2026

    The NextMove Lite – Thank You Page for WooCommerce plugin is vulnerable to stored cross-site scripting (XSS) via its 'xlwcty_current_date' shortcode. This vulnerability affects all versions up to and including 2.23.0 due to inadequate input sanitization and output escaping.

    MEDIUM (6.0)
    Plugin

    Stored XSS Vulnerability in Social Rocket Plugin via 'id' Parameter

    Published Date: Apr 23, 2026

    The Social Rocket – Social Sharing Plugin for WordPress is affected by a stored Cross-Site Scripting (XSS) vulnerability. This flaw allows authenticated users with Subscriber-level access or higher to inject arbitrary JavaScript into pages, potentially impacting site visitors and other users.

    MEDIUM (5.0)
    Plugin

    Gallagher Website Design Plugin Stored Cross-Site Scripting Vulnerability

    Published Date: Apr 22, 2026

    The Gallagher Website Design plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization in the 'prefix' attribute of the login_link shortcode. This flaw allows Contributor-level users and above to inject arbitrary scripts into pages, potentially executing malicious code when accessed by users.

    WordPress Vulnerabilities

    Updated every hour with the latest vulnerabilities

    Latest News and Digital Rights Updates

    Stay informed about the latest digital rights issues, threats, and community resources

    NDPC: 4,000 weekly cyberattacks push data localisation, stricter compliance
    May 2, 2026

    NDPC: 4,000 weekly cyberattacks push data localisation, stricter compliance

    Nigeria's burgeoning digital economy is currently grappling with a significant cybersecurity challenge, as it experiences over 4,000 cyberattacks weekly. This alarming trend underscores the urgent need for a comprehensive approach to data protection and its localization within national borders. The National Data Protection Commission (NDPC) has become a pivotal entity in advocating stricter regulatory compliance to safeguard both personal and organizational data. Another point of concern is the readiness of Nigerian organizations to counter such sophisticated cyber threats, highlighting the gaps in current security measures and their potential vulnerabilities. This situation calls for immediate action across several fronts, including enhancing cybersecurity infrastructure, adopting best practices for data management, and fostering a culture of cyber hygiene among businesses and consumers alike. Enhanced data localization measures are viewed as a strategic initiative to ensure that sensitive information is kept within the jurisdiction, offering additional layers of security and meeting international compliance standards. Consequently, the NDPC's push for stricter regulations is not just a reactive measure but a proactive stance aimed at fortifying Nigeria's digital space and instilling confidence among local and international stakeholders. As the country navigates this precarious landscape, collaboration between the government, private sector, and cybersecurity experts will be crucial in developing resilient systems to withstand and deter future cyber threats.

    NSA tests Anthropic’s Mythos AI for Microsoft cybersecurity flaws
    May 2, 2026

    NSA tests Anthropic’s Mythos AI for Microsoft cybersecurity flaws

    In a landmark move signaling the escalating role of artificial intelligence in cybersecurity, the National Security Agency (NSA) has embarked on testing Mythos AI, developed by Anthropic. This advanced AI tool is being used specifically to identify and address vulnerabilities within Microsoft's security infrastructure. The collaboration underscores a significant shift in defense strategies, as reliance on AI technologies grows to combat increasingly sophisticated cybersecurity threats. Mythos AI employs cutting-edge machine learning algorithms capable of scanning complex environments for potential security flaws that may otherwise go undetected by traditional methods. By integrating such technologies, the NSA hopes to bolster its defensive frameworks, ensuring more robust protection against potential cyber threats from nation-state actors and cybercriminals alike. The decision to involve Mythos AI represents a broader trend within national defense and technology sectors, highlighting an acute awareness of the evolving digital threat landscape. The inclusion of AI in these processes not only enhances the early detection of vulnerabilities but also expedites the time required to address them, consequently limiting exposure and risk. Furthermore, this partnership with Anthropic aligns with an industry-wide pivot towards automation and artificial intelligence, deemed essential in maintaining cybersecurity resilience. As governments and institutions continue to adapt to these changes, the insights garnered from such advanced technologies will likely inform future cybersecurity policies and defense mechanisms across both public and private sectors.

    2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware
    May 2, 2026

    2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware

    In a shocking revelation, two reputed U.S. cybersecurity professionals have been sentenced to prison for their involvement with the ALPHV (BlackCat) ransomware group. This case illustrates the evolving complexity of cybersecurity threats when insiders turn rogue. The accused were found guilty of exploiting their insider access to sensitive information, leveraging it for financial gains. By providing technical expertise and critical infrastructure support to the ransomware group, they facilitated global cyber extortions, marking a significant betrayal of trust within the cybersecurity community. The BlackCat ransomware group, notorious for its sophisticated operations and devastating cyber-attacks on businesses across the globe, has been one of the most persistent threats over the past year. The involvement of trusted experts in this illicit operation underscores the multifaceted challenges law enforcement faces in tracking and mitigating cybercrime. This case serves as a grim reminder of the need for robust internal security protocols, stringent access controls, and regular employee vetting in cybersecurity establishments. It also highlights the potential risks and ethical considerations related to working with cybersecurity professionals who possess deep knowledge of IT systems and networks. For the digital security industry, this incident triggers essential discussions on reinforcing the ethical dimensions of cybersecurity practices, alongside actionable preventive measures to deter insiders from abusing their positions of authority.

    Get Involved

    Join us in defending digital rights and protecting vulnerable communities.

    Donate

    Your contribution helps us provide free security resources to those who need them most.

    Volunteer

    Contribute your skills and time to support our mission and programs.

    Partner

    Collaborate with us on initiatives that advance digital rights and security.

    Let's Work Together

    Get in touch to discuss your needs or how you can support our mission

    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More