Get a Pentest and security assessment of your IT network.

Cyber Security

Critical Flaws in WordPress Quiz Plugin Allow Site Takeover

A plugin that is designed to add quizzes and surveys to WordPress websites has patched two critical vulnerabilities. The flaws can be exploited by remote, unauthenticated attackers to launch varying attacks including fully taking over vulnerable websites. The plugin, Quiz and Survey Master, is actively installed on over 30,000 websites. A patch is available for both issues in version 7.0.1 of the plugin, said researchers with Wordfence who discovered the flaws, in a Thursday post. The vulnerabilities stemmed from a feature in the plugin that enables site owners to implement file uploads as a response type for a quiz.

Source: https://threatpost.com/critical-flaws-wordpress-quiz-plugin-site-takeover/158379/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security