Get a Pentest and security assessment of your IT network.

News

Convert Plus WordPress plugin flaw allows hackers to create Admin accounts

The WordPress plugin Convert Plus is affected by a critical flaw that could be exploited by an unauthenticated attacker to create accounts with administrator privileges. The vulnerability ties with the lack of filtering when processing a new user subscription via a form implemented by the plugin that already has more than 100,000 active installations. Experts at Defiant discovered that Convert Plus plugin includes an administrator role in a hidden field called cp_set_user Experts pointed out that the value for this field could be supplied by the same HTTP request as the rest of the subscription entry, and users can modify it.”]

Source: https://securityaffairs.co/wordpress/86292/breaking-news/convert-plus-wordpress-flaw.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin