Many WordPress websites have come under attack via a zero-day flaw in an abandoned plugin. The Total Donations plugin, which was earlier used by many WordPress website owners, has now started creating issues. Security experts at Defiant, the company behind the Wordfence plugin for WordPress, have published details of the attack. They have advised website owners using the plugin to delete it from their servers. The plugins code has certain design flaws that would expose the plugin itself as well as the WordPress website to external manipulation.”]
Source: https://hackercombat.com/wordpress-websites-attacked-via-zero-day-in-abandoned-plugin/

