Get a Pentest and security assessment of your IT network.

Cyber Security

Critical WordPress Plugin Flaw Allows Complete Website Takeover

A critical vulnerability in popular WordPress plugin Simple Social Buttons enables non-admin users to modify WordPress installation options. The flaw allows privilege escalation, so that non-admins can take over administrator accounts or even whole websites. The vulnerability, rated 9.1 on the CVSS v3 severity scale, was discovered on Feb. 7, and a patch was released Feb. 8. Users of the plugin are urged to update to version 2.0.22.0. The plugin has more than 40,000 active installations, according to WordPress plugin repository.

Source: https://threatpost.com/wordpress-plugin-flaw-website-takeover/141746/

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation