Get a Pentest and security assessment of your IT network.

News

Critical auth bypass issues affect InfiniteWP Client and WP Time Capsule WordPress plugins

Security firm WebArx have ethically disclosed vulnerabilities in WP Time Capsule and InfiniteWP plugins. Both were patched earlier this month by the developer Revmakx. The flaws could be exploited to take over websites running the popular CMS that are more than 320,000. The issue resides in the function iwp_mmb_set_request which is located in the init.php file. To bypass the authentication the attackers need to send a POST request containing in the body a certain string. The request will bypass the password requirement and log in with only the username of an existing account.”]

Source: https://securityaffairs.co/wordpress/96477/hacking/wordpress-plugin-flaws.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months