Get a Pentest and security assessment of your IT network.

Cyber Security

Anti-Spam WordPress Plugin Could Expose Website User Data

Spam protection, AntiSpam, FireWall by CleanTalk is installed on more than 100,000 sites. The issue (CVE-2021-24295, which carries a high-severity CVSS vulnerability rating of 7.5 out of 10) arises thanks to how it performs that filtering. It maintains a blocklist and tracks the behavior of different IP addresses, including the user-agent string that browsers send to identify themselves. Researchers were able to successfully exploit the vulnerability via the time-based vulnerability in CleanTalk.

Source: https://threatpost.com/anti-spam-wordpress-plugin-expose-data/165901/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security