Planet Nexus Support Forum
  • Portal
  • Web Home
  • Search
  • Members
  • System
    • NexAds
    • NexAds FAQ
    • Sites Roster
    • Stats Wall
    • Help Docs
    • Rules
    • Unread Posts
    • Today's Posts
Login or Register Hello There, Guest! Please Login or Register to gain Full Access!
Login for NexAds and Support Access
Username:
Password: Lost Password?
 

  1. Planet Nexus
  2. Planet Control
  3. Service Discussion & Feedback
  4. A critical flaw uncovered In WordPress, please update now!
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5

Thread Modes
A critical flaw uncovered In WordPress, please update now!
Skyon Archer
Lead Developer
Posts: 1,412
Threads: 71
Joined: Jul 2018
Reputation: 9
My TimeZone: -6
#1
02-23-2019, 01:50 PM
A critical flaw uncovered In WordPress, please update now!

[Image: IPrto.jpg]

Just a few days ago, security researchers made public a critical flaw in all WordPress versions, which are older than 4.9.9. 

The flaw allows anyone with “author” privileges to completely gain control over a WordPress website. All WordPress versions from the last 6 years are affected.

If you are using a WordPress version, which is older than 4.9.9, you have to update to the latest version immediately so as to protect yourself from this vulnerability.

Even though the attack vector requires a profile with “author” privileges, access to such an account can be gained via multiple methods like phishing, password reuse, etc.

Once the attacker gains access to such an account, they can execute PHP code on the server, effectively taking over the whole WordPress website.

More information about this new vulnerability can be found in the original report from RIPS Technologies GmbH.

TierraHost.com - TierraHosting.com - TierraHosting.net - Tierra.Hosting - TierraHosting.us - YourDomainNinja.com - SpicesDomains.com - BaratoDomains.com
Website Find
Reply
Helena
The Boss
Posts: 1,265
Threads: 92
Joined: Jul 2018
Reputation: 9
My TimeZone: -6GMT USA
#2
02-23-2019, 02:45 PM
So if I understand this article correctly, even if your WordPress installation is at 5.1 (latest) the vulnerability still exists if you have old plug ins?

 [Image: I1mX7.png] Follow Planet Nexus   #nexads

[Image: bMr7N.png] Like us on Facebook #myNexAds ~ Please share the pinned post to your timeline



Website Find
Reply
Skyon Archer
Lead Developer
Posts: 1,412
Threads: 71
Joined: Jul 2018
Reputation: 9
My TimeZone: -6
#3
02-23-2019, 03:00 PM
If the plugin processes it's own uploads then yes; however, as the article indicated, there are specific authentication steps that must be completed for this to happen.

This is one of the reasons that I recommend to NOT use plugins to all my WordPress hosting clients; excluding those that are actively maintained by trusted sources (i.e. contact form 7, jetpack, etc).

TierraHost.com - TierraHosting.com - TierraHosting.net - Tierra.Hosting - TierraHosting.us - YourDomainNinja.com - SpicesDomains.com - BaratoDomains.com
Website Find
Reply
« Next Oldest | Next Newest »


  • View a Printable Version
  • Subscribe to this thread
Forum Jump:


Users browsing this thread: 1 Guest(s)

About Planet Nexus

Support and discussion forum for our Nexworking subscribers and friends.
Welcome to Planet Nexus!

Quick Links



Reach Us

Contact Us  Meet Our team

Powered By MyBB - Hosted by Tierra Hosting Index
 
TOP
Linear Mode
Threaded Mode