Get a Pentest and security assessment of your IT network.

Cyber Security

Ninja Forms WordPress Plugin Opens Websites to Hacks

Ninja Forms is a WordPress plugin used by more than 1 million sites. It has four flaws that allow various kinds of serious attacks, including site takeover and email hijacking. The four bugs allow lower-privileged users (even those who have registered for a site) to carry out a range of malicious activity. They include eavesdropping on site email, taking over admin accounts, installing arbitrary add-ons to a target site and redirecting site owners to malicious destinations. Three of the bugs do require social engineering to be successful.

Source: https://threatpost.com/ninja-forms-wordpress-plugin-hacks/164042/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security