Get a Pentest and security assessment of your IT network.

News

Critical Remote Code Execution Flaw Found in WordPress Plugin

There is an easily exploitable remote code execution vulnerability in a popular WordPress plugin that helps manage file downloads. Researchers at Sucuri discovered the vulnerability and a fixed version of the plugin was released earlier this week. The vulnerability is in the WP Download Manager, versions 2.7.4 and lower, and it could be used to implant a backdoor on a vulnerable site or get access to admin accounts. The bug in the plugin is caused by an Ajax function that didn t enforce permission checks.

Source: https://threatpost.com/critical-remote-code-execution-flaw-found-in-wordpress-plugin/109720/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

1 day attack with DDoS booter costs $60 causing $720k in damageSecurity Affairs

News

NSA-linked Cisco exploit poses bigger threat than previously thought