Get a Pentest and security assessment of your IT network.

News

Unpatched WordPress file deletion vulnerability could allow site takeover and code execution

Seven months ago, security experts discovered a critical file deletion vulnerability that affects all WordPress versions. The vulnerability could be exploited to complete takeover of the websites running the popular CMS and gain arbitrary code execution. The flaw resides in the WordPress Core, the code to trigger it was found in the wp-includes/post.php file: $meta[thumb is used to invoke the unlink() function without undergoing any sanitization. An arbitrary file deletion flaw occurs when it is possible to pass unsanitized input to a file deletion function.”]

Source: https://securityaffairs.co/wordpress/73944/hacking/wordpress-file-deletion-vulnerability.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin