Get a Pentest and security assessment of your IT network.

Cyber Security

WordPress Yellow Pencil Plugin Flaws Actively Exploited

Yellow Pencil Visual Theme Customizer plugin is being exploited in the wild after two software vulnerabilities were discovered. The attacker exploiting these flaws has been behind several other recent plugin attacks, researchers said. The vulnerability exists in a privilege-escalation vulnerability that exists in its yellow-pencil.php file. The second flaw is a cross-site request forgery (CSRF) check that is missing in the function below that would have made it much more difficult to exploit, they said. Users are urged to update to the latest version of the plugin, 7.2.0.

Source: https://threatpost.com/wordpress-yellow-pencil-plugin-exploited/143729/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security