Get a Pentest and security assessment of your IT network.

News

Security Advisory High Severity WordPress Download Manager

The vulnerability was discovered and disclosed last week and immediately patched by the WP Download Manager plugin. The plugin used a custom method to handle certain types of Ajax requests which could be abused by an attacker to call arbitrary functions within the applications context. There were no permission checks before handling these special Ajax calls. The culprit was in the wpdm_ajax_call_exec() function. The function is hooked to the WP hook (which is executed every single time somebody visits a post/page) It could be used to upload a backdoor and change important credentials, like admin accounts.”]

Source: https://blog.sucuri.net/2014/12/security-advisory-high-severity-wordpress-download-manager.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin