WordPress Plugin Flaw Exposes 200,000 WordPress Sites To Hacking
- С сайта: Vulnerability(cybersecuritynews.com)
- Вернуться к списку новостей
WordPress Plugin Flaw Exposes 200,000 WordPress Sites To Hacking
Author: Tushar Subhra DuttaA critical vulnerability was discovered on October 30th, 2024 in the Anti-Spam by CleanTalk WordPress plugin, potentially affecting over 200,000 active installations.
This flaw allows unauthenticated attackers to install and activate arbitrary plugins, which could lead to remote code execution on vulnerable sites.
Vulnerabilities that were discovered in the WordPress plugin are tracked as “CVE-2024-10542” and “CVE-2024-10781.”
Wordfence researchers identified that these two vulnerabilities were marked with the “Critical” tag with the score of 9.8 for both the vulnerabilities.
Here below we have mentioned the complete flaw profile for the above-mentioned two vulnerabilities that were identified in the plugin:-
Authorization Bypass via Reverse DNS Spoofing
- Affected versions:
#Cyber_Security_News #Vulnerability #cyber_security_news #vulnerability
Оригинальная версия на сайте: