Security firm WebArx have ethically disclosed vulnerabilities in WP Time Capsule and InfiniteWP plugins. Both were patched earlier this month by the developer Revmakx. The flaws could be exploited to take over websites running the popular CMS that are more than 320,000. The issue resides in the function iwp_mmb_set_request which is located in the init.php file. To bypass the authentication the attackers need to send a POST request containing in the body a certain string. The request will bypass the password requirement and log in with only the username of an existing account.”]
Source: https://securityaffairs.co/wordpress/96477/hacking/wordpress-plugin-flaws.html

