Get a Pentest and security assessment of your IT network.

News

Vulnerability in AMP for WP Plugin Allowed Admin Access to WordPress

A vulnerability for the popular AMP for WP plugin allows any registered user to escalate their privileges to gain administrative access to the site. The vulnerability was caused by the plugin not properly utilizing WordPress nonces and the current_user_can() function in various administrative functions. The vulnerabilities have been fixed in version 0.9.97.20, which was released two weeks ago and is available through WordPress’ automatic update feature. As many publishers, though, do not utilize this feature, they would remain unprotected.

Source: https://www.bleepingcomputer.com/news/security/vulnerability-in-amp-for-wp-plugin-allowed-admin-access-to-wordpress/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Reflection of cyber-attack to Wells Fargo in world media

News

CVE-2016-6563 RCE flaw affects D-Link Routers, disable remote admin