Get a Pentest and security assessment of your IT network.

Cyber Security

Thousands of WordPress Sites Exposed by Yellow Pencil Plugin Flaw

The Yellow Pencil Visual Theme Customizer plugin was removed from the WordPress.org repository on Monday. The vulnerability was discovered in the plugin with an install base of more than 30,000 websites. Attackers could potentially change both the site and the home URLs with an unauthenticated SQL injection. Researchers say the vulnerability is part of a larger campaign run by the same threat actor. The plugin’s developers have fixed the vulnerability with the 7.2.0 version of the YellowPencil plugin and are now providing a download link to apply the patch.

Source: https://www.bleepingcomputer.com/news/security/thousands-of-wordpress-sites-exposed-by-yellow-pencil-plugin-flaw/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security