cognitive cybersecurity intelligence

News and Analysis

Search

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

Critical WordPress Plugin Flaw Puts Over 10,000 Sites of Cyberattack

A serious security flaw has been found in the Eventin plugin for WordPress, potentially exposing over 10,000 sites to cyberattacks. The flaw allowed any unauthenticated user administrative access to a site. Patchstack Alliance community member, Denver Jackson, discovered the flaw, which resided in the plugin’s REST API and was due to a lack of permission checks. Eventin has since addressed the vulnerability in Version 4.0.27.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts