Users Urged to Disable WordPress Plugin After Unpatched Flaw Disclosed
#1
Quote:An unpatched vulnerability in a popular WordPress plugin called the WooCommerce Checkout Manager extension is potentially putting more than 60,000 websites at risk, researchers say.
 
The WooCommerce Checkout Manager plugin allows WooCommerce users to customize and manage the fields on their checkout pages. The plugin, owned by Visser Labs, is separate from the WooCommerce plugin, which is owned by Automattic.
 
“Earlier this week, an arbitrary file upload vulnerability has been found in popular WordPress plugin WooCommerce Checkout Manager which extends the functionality of well known WooCommerce plugin,” said Luka Sikic, with WebArx Security in a Thursday post.

Visser Labs has not responded to a request for comment from Threatpost. On Friday, the plugin has been removed from the WordPress plugin repository. “This plugin was closed on April 26, 2019 and is no longer available for download,” according to a notice on the site. However, that still leaves the 60,000 websites who have already downloaded and are utilizing the plugin open to attack, according to researchers.

SOURCE: https://threatpost.com/users-urged-to-di...ed/144159/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AirVPN
AirVPN Suite versi...jasonX — 05:33
Surfshark VPN : Award-winning VPN servi...
SASE vs. VPNs: whi...jasonX — 05:23
Surfshark VPN : Award-winning VPN servi...
VPC vs. VPN: what’...jasonX — 03:05
HitmanPro.Alert 3.21.1 Build 2047 (stabl...
HitmanPro.Alert 3....harlan4096 — 11:43
Apple Releases iOS 26.4.2 and iPadOS 26....
Apple has just rel...harlan4096 — 11:41

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (51)Toligo

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>