Critical WordPress Plugin Flaw Allows Site Takeover
#1
Information 
Quote:Researchers are urging WordPress websites that utilize the NextGen Gallery plugin to apply a patch addressing critical and high-severity flaws.
 
The NextGen Gallery plugin, which is installed on 800,000 WordPress websites, allows sites to upload photos in batch quantities, import metadata and edit image thumbnails. Researchers discovered two cross-site request forgery (CSRF) flaws – one critical and one high-severity – in the plugin.
 
A patch was released for flaws in version 3.5.0, on Dec. 17. In the first public disclosure of details of the flaw, released Monday, researchers urged website owners who use the plugin to ensure they are updated.

“Exploitation of these vulnerabilities could lead to a site takeover, malicious redirects, spam injection, phishing and much more,” said Ram Gall with Wordfence, on Monday.

CSRF is a type of web flaw that allows an attacker to trick web browsers into performing malicious, unauthorized commands. Typically, CSRF attacks are carried out by attackers with a link sent to the victim – and using social engineering to persuade them to click on it. When victims click on the link, they are inadvertently sending a forged request to a server – resulting in the attacker being able to perform various commands.

Read more: https://threatpost.com/critical-wordpres...er/163734/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Critical WordPress Plugin Flaw Allows Site Takeover - by silversurfer - 09 February 21, 11:42

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 151.0.1
Mozilla Firefox Br...harlan4096 — 08:57
AnyDesk 9.7.4 for Windows
Version 9.7.4 for ...harlan4096 — 08:55
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 08:52
Brave 1.90.124 (Chromium 148.0.7778.179)
Release v1.90.124 ...harlan4096 — 08:49
Screenpresso 2.2.12
Screenpresso 2.2.1...harlan4096 — 08:42

[-]
Birthdays
Today's Birthdays
avatar (50)Mirzojap
avatar (36)idilysaju
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>