Get a Pentest and security assessment of your IT network.

News

WordPress silently fixes dangerous code injection vulnerability

Vulnerability was discovered by researchers from web security firm Sucuri and was reported privately to the WordPress team on January 20. It’s located in the platform’s REST API (application programming interface) and allows unauthenticated attackers to modify the content of any post or page within a WordPress site. The vulnerability only affects WordPress 4.7.7 and 4.1, where the REST API is enabled by default. Older versions are not affected, even if they have the API plug-in. Developers say they intentionally delayed disclosing this issue by one week to ensure the safety of millions of additional WordPress sites.”]

Source: https://www.csoonline.com/article/3164554/wordpress-silently-fixes-dangerous-code-injection-vulnerability.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months