WordPress, WooCommerce flaws combine to allow website hijacking
#1
Quote:A flaw in how WordPress handles privilege assignments can be exploited to permit attackers to hijack WooCommerce websites.

The issue in the content management system (CMS) was discovered by Simon Scannell, a security researcher from RIPS Technologies, who said in a blog post that the design flaw specifically impacts WooCommerce, a popular WordPress plugin which has been downloaded over four million times.

"The vulnerability allows shop managers to delete certain files on the server and then to take over any administrator account," the security researcher says.

The plugin has been developed by Automattic and is a free e-commerce system for WordPress-based websites.

A file deletion bug was found in the software, and on its own, would generally not be considered critical as the best an attacker could do would be to delete index.php pages and cause a denial of service. However, when coupled with the WordPress design flaw, the bug's severity increases.

Source: https://www.zdnet.com/article/wordpress-...hijacking/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] HitmanPro.Alert Mother'...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
GFYI [Official] Master PDF Editor Mothe...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
ON1 Software
  20 Years of O...jasonX — 05:02
Celebrating 20 Years of ON1: ON1 Photo C...
Celebrating 20 Years...jasonX — 05:00
AntGROUP Inc. / VCap-developer
VCap Downloader ...jasonX — 04:58

[-]
Birthdays
Today's Birthdays
avatar (47)vadimTob
avatar (37)leannauu4
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
harlan4096's profile harlan4096
Administrator
jasonX's profile jasonX
Administrator

>