WordPress Theme & Plugin Vulnerabilities Exposes Thousands of Sites
- С сайта: Vulnerability(cybersecuritynews.com)
- Вернуться к списку новостей
WordPress Theme & Plugin Vulnerabilities Exposes Thousands of Sites
Author: DhivyaThousands of WordPress sites have been exposed to potential threats due to vulnerabilities in the Houzez theme and WordPress Houzez Login Register plugin.
The flaw isidentified as CVE-2024-22303 and CVE-2024-21743. It affects versions up to 3.2.4 and 3.2.5 and is classified as a high-priority issue with a CVSS score of 8.8, indicating significant risk.
CVE-2024-22303 – WordPress Houzez Theme Vulnerability
The vulnerability allows privilege escalation, enabling malicious actors to elevate their access from low-privileged accounts to higher privileges.
This could potentially lead to complete control over the affected website. The issue is categorized under the OWASP Top 10 as A5: Security Misconfiguration.
Patch and Mitigation
Patchstack has released a virtual patch to mitigate this vulnerability until users can update to the fixed version, 3.3.0. Website administrators are strongly advised to update immediately to prevent exploitation.
Details Information Software Houzez Type Theme Vulnerable Versions
#Cyber_Security #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news #vulnerability
Оригинальная версия на сайте: