|

Linked: Critical WordPress Plugin Bug Allows Admin Logins Without Password

It’s been patched, so if you’re behind on your WordPress plugin upgrades, get with it.

“A critical authentication bypass vulnerability allows anyone to log in as an administrator user on WordPress sites running an affected version of the InfiniteWP Client because of logical mistakes in the code.”

One of the challenges of hosting your own WordPress site is updates. I’ve learned this the hard way years ago by leaving an old install laying around without keeping it updated. It’s sort of an open invitation for hackers to take over a site using known vulnerabilities.

This one seems easy enough to fix, so get the update before someone uses that vulnerability against you.

https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-allows-admin-logins-without-password/

Similar Posts

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)