Get a Pentest and security assessment of your IT network.

News

Severe SQL Injection Flaw Discovered in WordPress Plugin with Over 1 Million Installs

A WordPress plugin installed on over one million sites has just fixed a severe SQL injection vulnerability that can allow attackers to steal data from a website’s database. The vulnerable plugin’s name is NextGEN Gallery, a plugin so successful that it has its own set of plugins. The vulnerability was discovered by web security firm Sucuri. Sucuri gave this vulnerability a score of 9 out of 10, mainly due to how easy was it to exploit the flaw, even for non-technical attackers. The plugin’s authors fixed this flaw in Nextgen Gallery 2.1.79.

Source: https://www.bleepingcomputer.com/news/security/severe-sql-injection-flaw-discovered-in-wordpress-plugin-with-over-1-million-installs/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Reflection of cyber-attack to Wells Fargo in world media

News

CVE-2016-6563 RCE flaw affects D-Link Routers, disable remote admin