Source |
The Hacker News |
Identifiant |
4148874 |
Date de publication |
2022-02-18 22:25:08 (vue: 2022-02-19 07:05:49) |
Titre |
Critical Flaw Uncovered in WordPress Backup Plugin Used by Over 3 Million Sites |
Texte |
Patches have been issued to contain a "severe" security vulnerability in UpdraftPlus, a WordPress plugin with over three million installations, that can be weaponized to download the site's private data using an account on the vulnerable sites.
"All versions of UpdraftPlus from March 2019 onwards have contained a vulnerability caused by a missing permissions-level check, allowing untrusted users |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2019 account all allowing backup been can caused check contain contained critical data download flaw from have installations issued level march million missing onwards over patches permissions plugin private security severe site sites three uncovered untrusted updraftplus used users using versions vulnerability vulnerable weaponized wordpress |
Tags |
Vulnerability
|
Stories |
|
Move |
|