Defending Your Digital Rights

    A non-profit organization committed to protecting digital freedoms, privacy, and security for vulnerable communities worldwide.

    About Us

    We are a collective of digital rights advocates, security experts, and educators committed to empowering individuals and communities with the knowledge and tools to protect their digital freedoms.

    Our Initiatives

    How we work to protect digital rights and empower communities

    Awareness

    Raising awareness about digital rights, privacy threats, and security best practices.

    Advocacy

    Advocating for policies and regulations that protect digital rights and freedoms.

    Education

    Providing training and resources on digital security for vulnerable groups.

    Support

    Offering direct assistance to individuals and organizations facing digital threats.

    Community Building

    Creating networks of digital rights defenders to share knowledge and resources.

    Collaboration

    Working with partners globally to develop solutions to digital security challenges.

    Security Alerts

    Latest WordPress security vulnerabilities affecting plugins, themes, and core.

    MEDIUM (5.4)
    Plugin

    Stored XSS Vulnerability in Social Rocket Plugin via 'id' Parameter

    Published Date: Apr 23, 2026

    The Social Rocket – Social Sharing Plugin for WordPress is affected by a stored Cross-Site Scripting (XSS) vulnerability. This flaw allows authenticated users with Subscriber-level access or higher to inject arbitrary JavaScript into pages, potentially impacting site visitors and other users.

    MEDIUM (6.5)
    Plugin

    Gallagher Website Design Plugin Stored Cross-Site Scripting Vulnerability

    Published Date: Apr 22, 2026

    The Gallagher Website Design plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization in the 'prefix' attribute of the login_link shortcode. This flaw allows Contributor-level users and above to inject arbitrary scripts into pages, potentially executing malicious code when accessed by users.

    MEDIUM (6.6)
    Plugin

    Gutentools Plugin Stored Cross-Site Scripting Vulnerability via Post Slider Block

    Published Date: Apr 22, 2026

    The Gutentools plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability in the Post Slider block's block_id attribute, affecting versions up to and including 1.1.3. Authenticated users with Contributor-level access and above can exploit this flaw to inject malicious scripts into pages.

    WordPress Vulnerabilities

    Updated every hour with the latest vulnerabilities

    Latest News and Digital Rights Updates

    Stay informed about the latest digital rights issues, threats, and community resources

    Australian banks warned frontier AI could create larger, faster cyber attacks
    April 30, 2026

    Australian banks warned frontier AI could create larger, faster cyber attacks

    In a sobering warning, the Australian Prudential Regulation Authority (APRA) has signaled increasing cyber threats against the banking sector, driven by the rapid evolution of frontier artificial intelligence. Tools such as Anthropic's Claude Mythos, a highly advanced AI system, pose potential risks as they can be exploited by cybercriminals to develop more sophisticated and quicker cyber attacks. The concern stems from AI's ability to automate processes that previously required significant manual input, thus enhancing both the speed and scale of potential cyber threats. Banks, which traditionally guard some of the most sensitive customer information, now face challenges that require urgent attention and adaptation to evolving technologies. Current cybersecurity protocols, while robust in some respects, may not be adequate against the lightning speed and advanced strategies AI can offer to malicious actors. This scenario urges not only financial institutions but all digital entities, including WordPress website owners, to reassess their security frameworks significantly. The ability of AI to outpace current security measures means institutions must innovate continuously, employing AI for defense as much as they are threatened by it in offense. The recommendation for financial entities is clear: adopt an AI-driven defensive stance, enhance threat detection and response times, and foster a more cohesive cybersecurity ecosystem across sectors. The pressing need is to strike a balance between leveraging AI for enhanced customer services and securing sensitive data against potential intrusions. As regulators bring this to the forefront, an industry-wide collaborative effort will be fundamental to developing resilient infrastructures capable of defending against emerging AI-driven cyber threats.

    Popular WordPress redirect plugin hid dormant backdoor for years
    April 29, 2026

    Popular WordPress redirect plugin hid dormant backdoor for years

    The recent discovery of a dormant backdoor in the Quick Page/Post Redirect plugin has sounded alarm bells across the WordPress community. This popular plugin, utilized by more than 70,000 websites, harbored a concealed backdoor for five years. The vulnerability allowed malicious actors to inject arbitrary code into the users' sites, potentially compromising sensitive data and undermining site integrity. This incident highlights the enduring threat of hidden vulnerabilities within third-party plugins that are both unnoticed by developers and unappreciated by users. The backdoor remained undetected for half a decade, underscoring the need for continuous vigilance and regular security audits. This discovery has sent ripples of concern across webmasters and security experts alike, prompting immediate action to mitigate potential damage. Website owners who deployed this plugin are advised to review their site security protocols, update or replace compromised plugins, and monitor for unusual activity. This event serves as a crucial reminder of the inherent risks posed by third-party plugins and the necessity for robust WordPress security measures.

    Cyberattacks surge across UAE amid Iran conflict, businesses face disruptions and rising risks
    April 29, 2026

    Cyberattacks surge across UAE amid Iran conflict, businesses face disruptions and rising risks

    In light of the escalating tensions in the Gulf, particularly between Iran and other regional powers, the United Arab Emirates is experiencing an unprecedented surge in cyberattacks. These digital assaults have primarily targeted financial services, government platforms, and critical utility infrastructure, effectively tripling in frequency and significantly disrupting business operations. Businesses across the region are facing considerable delays and financial losses as they scramble to mitigate these threats. Experts in cybersecurity warn that the geopolitical context has substantially increased the region's vulnerability to cyber threats, amplifying risks not just for large organizations but also for medium and small-sized enterprises. Additionally, the attacks are becoming more sophisticated, utilizing advanced tactics that evade traditional security measures. Organizations are urged to enhance their cybersecurity infrastructure, implement robust monitoring and incident response plans, and foster a culture of security awareness among employees. As digital interconnectivity grows, protecting against cyberattacks becomes a foundational element for maintaining business continuity in the Gulf's dynamic economic landscape.

    Get Involved

    Join us in defending digital rights and protecting vulnerable communities.

    Donate

    Your contribution helps us provide free security resources to those who need them most.

    Volunteer

    Contribute your skills and time to support our mission and programs.

    Partner

    Collaborate with us on initiatives that advance digital rights and security.

    Let's Work Together

    Get in touch to discuss your needs or how you can support our mission

    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More