Critical WordPress Plugin Flaw Allows Site Takeover
#1
Information 
Quote:Researchers are urging WordPress websites that utilize the NextGen Gallery plugin to apply a patch addressing critical and high-severity flaws.
 
The NextGen Gallery plugin, which is installed on 800,000 WordPress websites, allows sites to upload photos in batch quantities, import metadata and edit image thumbnails. Researchers discovered two cross-site request forgery (CSRF) flaws – one critical and one high-severity – in the plugin.
 
A patch was released for flaws in version 3.5.0, on Dec. 17. In the first public disclosure of details of the flaw, released Monday, researchers urged website owners who use the plugin to ensure they are updated.

“Exploitation of these vulnerabilities could lead to a site takeover, malicious redirects, spam injection, phishing and much more,” said Ram Gall with Wordfence, on Monday.

CSRF is a type of web flaw that allows an attacker to trick web browsers into performing malicious, unauthorized commands. Typically, CSRF attacks are carried out by attackers with a link sent to the victim – and using social engineering to persuade them to click on it. When victims click on the link, they are inadvertently sending a forged request to a server – resulting in the attacker being able to perform various commands.

Read more: https://threatpost.com/critical-wordpres...er/163734/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Microsoft confirms Windows 11 version 2...
Microsoft Confirms W...harlan4096 — 08:41
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46
Windows 11 June 2026 Update Breaks Recyc...
Microsoft has conf...harlan4096 — 11:45

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>