Get a Pentest and security assessment of your IT network.

Cyber Security

WP Live Chat WordPress Plugin Re-Patches File Upload Flaw

A WordPress plugin vulnerability found in WP Live Chat could allow an attacker to upload arbitrary malicious files to vulnerable systems. A previously-discovered critical arbitrary file upload flaw (CVE 2018 12426) was patched in the plugin but researchers on Monday said they were able to bypass that fix in a proof-of-concept attack. The new fix stems from a glitch in the validation functions of the plugin for checking if an uploaded file is not malicious. File upload vulnerabilities used against WordPress are prevalent and easy for attackers to exploit.

Source: https://threatpost.com/wp-live-chat-wordpress-plugin-re-patches-file-upload-flaw/144420/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security