Get a Pentest and security assessment of your IT network.

Cyber Security

Tutor LMS for WordPress Open to Info-Stealing

Security vulnerabilities in Tutor LMS, a WordPress plugin, open the door to information theft and privilege escalation. Five critical flaws in the plugin, including one high-severity bug stemming from unprotected AJAX endpoints. The five vulnerabilities all rate 6.5 out of 10 on the CVSS vulnerability-rating scale, making them medium in severity. The remaining flaws allow authenticated attackers to elevate user privileges and alter course content and settings, through the use of various AJAX actions. Site administrators should update to the patched version of the plugin.

Source: https://threatpost.com/tutor-lms-wordpress-security-holes/164868/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security