Get a Pentest and security assessment of your IT network.

Cyber Security

WordPress Slick Popup Plugin Contains Vulnerable Support Backdoor

Hackers can take over WordPress websites running Slick Popup plugin by enabling a backdoor administrator account with hardcoded credentials. The vulnerability is active at the moment and affects all versions of the plugin up to 1.7.1 – which is currently the latest release. The developer has not come up with a fix for the vulnerability a month after acknowledging it. Deactivating or deleting the plugin are two recommendations to ensure that a website running it remains safe. The plugin is designed to customize how and where the Contact Form 7 plugin is displayed on webpages.

Source: https://www.bleepingcomputer.com/news/security/wordpress-slick-popup-plugin-contains-vulnerable-support-backdoor/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security