A popular WordPress plugin could be putting around two million websites at risk of attack. Millions of WordPress-powered websites are using the Advanced Custom Fields and Advanced Custom Fields Pro ... Threat Post: Three Plugins with Same Bug Put 84K WordPress Sites at Risk A flaw in a WordPress anti-spam plugin with over 200,000 installations allows rogue plugins to be installed on affected websites.

Understanding the Context

Security researchers rated the vulnerability 9.8 out of 10, reflecting ... An advisory was issued for a critical vulnerability rated 9.8/10 in the CleanTalk Antispam WordPress plugin, installed in over 200,000 websites. The vulnerability enables unauthenticated attackers to ... Ars Technica: Hackers try to exploit WordPress plugin vulnerability that’s as severe as it gets Hackers are assailing websites using a prominent WordPress plugin with millions of attempts to exploit a high-severity vulnerability that allows complete takeover, researchers said.

Key Insights

The vulnerability ... Hackers try to exploit WordPress plugin vulnerability that’s as severe as it gets A US-based cyber-security firm has published details about two zero-days that impact two of Facebook's official WordPress plugins. The details also include proof-of-concept (PoC) code that allows ...