Get a Pentest and security assessment of your IT network.

Cyber Security

Critical WordPress plugin bug allows for automated takeovers

A critical vulnerability in the WP Product Review Lite plugin can be remotely exploited by unauthenticated attackers. Attackers can bypass the WordPress user input data sanitization function to launch Stored Cross-Site Scripting (Stored XSS) attacks which, on successful exploitation, allows them to inject malicious scripts in all the products stored in the targeted site s database. The vulnerability was fixed in version 3.7.6 released on May 14, one day after Sucuri Labs reported it. Over 33,000 sites running vulnerable versions of the plugin still being exposed to attacks.

Source: https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-allows-for-automated-takeovers/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security