200K WordPress Sites Vulnerable to Plugin Flaw
#1
Information 
Quote:A high-severity vulnerability exists in a popular WordPress plugin, potentially opening up 200,000 websites to takeover.
 
The WordPress plugin in question in Code Snippets, which allows users to run small chunks of PHP code on their websites. This can be used to extend the functionality of the website (essentially used as a mini-plugin). The flaw (CVE-2020-8417) has been patched by the plugin’s developer, Code Snippets Pro.
 
“This is a high severity security issue that could cause complete site takeover, information disclosure, and more,” said Chloe Chamberland with Wordfence, who discovered the flaw, in an analysis this week. “We highly recommend updating to the latest version (2.14.0) immediately.”
 
Code Snippets offers an import menu for importing code onto the website. However, researchers found that the import menu had a missing referrer check, which allows a webpage to see where requests originated. That means malicious code could be enabled upon import.
 
That opens affected websites up to cross-site request forgery (CSRF), an attack that forces a victim (once they click on a malicious link) to execute unwanted actions on web applications in which they’re currently authenticated.

Read more: https://threatpost.com/200k-wordpress-si...aw/152415/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD DGF SuperCompression cuts geometry s...
AMD’s DGF SuperCom...harlan4096 — 07:21
uBOLite 2026.510.1607 (already available...
uBOLite 2026.510.1...harlan4096 — 07:19
Chrome for Android Adds Approximate Loca...
Google is introduc...harlan4096 — 07:18
AdGuard Browser Extension 5.4.2.0
AdGuard Browser Ex...harlan4096 — 11:45
Cracked in under a minute: (nearly) ever...
We’ve revisited ou...harlan4096 — 11:44

[-]
Birthdays
Today's Birthdays
avatar (41)axylisyb
avatar (44)tukrublape
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>