A security expert discovered a critical vulnerability in the PHPMailer that leaves millions of websites vulnerable to remote exploit. The flaw was discovered by the notorious security expert Dawid Golunski from Legal Hackers. It could be exploited by a remote unauthenticated attacker to execute arbitrary code in the context of the web server and compromise the target web application. The vulnerability affects all versions of the library used to send emails using PHP and popular CMS, including WordPress, Drupal, and Joomla.”]
Source: https://securityaffairs.co/wordpress/54759/hacking/phpmailer-cve-2016-10033-flaw.html

