Four vulnerabilties, including a critical SQL injection, in WPML (sitepress-multilingual-cms) WordPress plug-in.
Patch available. Updated March 13.
Read more »
January 31, 2015
Another 0-day to be released soon: WordPress 3.0 - 4.1.1 core stored XSS, vendor notified on November 7.
Same impact as the previous but more restricted attack vector.