|

Linked: Critical WordPress Plugin Bug Allows Admin Logins Without Password

It’s been patched, so if you’re behind on your WordPress plugin upgrades, get with it.

“A critical authentication bypass vulnerability allows anyone to log in as an administrator user on WordPress sites running an affected version of the InfiniteWP Client because of logical mistakes in the code.”

One of the challenges of hosting your own WordPress site is updates. I’ve learned this the hard way years ago by leaving an old install laying around without keeping it updated. It’s sort of an open invitation for hackers to take over a site using known vulnerabilities.

This one seems easy enough to fix, so get the update before someone uses that vulnerability against you.

https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-allows-admin-logins-without-password/

Similar Posts

  • |

    Public Speaking as an Introvert – It’s About the Message

    Yesterday I blogged about an interview with Kevin Briggs, who is a suicide prevention advocate who used to be a patrolman on the Golden gate bridge. Obviously, over on that site, it was that work that was the priority, but I wanted to share something else he said in that interview, as both a blogger…

  • New stuff

    If you subscribe to the feed, you may have noticed the new “links of the day” item earlier this morning. One of the things I get with Feedburner is the ability to show you a post with all the stuff I linked on my Bloglines link blog for that day. I figure it’s a good…

  • Links (weekly)

    The Dangers of Do-It-Yourself eDiscovery: A Warning to Lawyers and Business Leaders. tags: LitSupport MM eDiscovery is Just Discovery tags: LitSupport MM The Growing Mobile Forensic Headache tags: LitSupport MM After SOPA/PIPA? tags: Tech MM Taking passwords seriously tags: Tech MM 5 Tips for Breaking Into Litigation Support tags: LitSupport MM Bottom Line Driven Proportional…

  • This Week’s Links (weekly)

    10 Body Language Tips Every Speaker Must Know (Infographic) tags: Training MM France Just Made It Illegal To Answer Work Emails After 6 P.M. tags: Management MM OLP Launches the First Litigation Support Certification Exam: First of its kind will set industry standards tags: LitSupport MM Mobile Apps Are Killing The Free Web, Handing A…

  • |

    What I’m Sharing (weekly) Sept. 13, 202

    The Perfect Preservation Letter: A New Guide

    Is Flexible Work the New Normal? Survey Says It Is Good For Mental Health

    The coming wave of Covid-related age discrimination lawsuits

    – Employers need to be vigilant in laying off older workers. “High risk for Covid” and “highly compensated” might by proxies for age discrimination.

    Amid COVID-19, people under 30 may finally kill email

    Will lawyers be replaced by GPT-3? Yes, and here’s when

    Fake LinkedIn Accounts – What to Do and What LinkedIn is Doing

    One Ethics Rule Leads to Another: Technology Competence and the Duty of Supervision

    Remote Networking as a Person of Color

    Burnout Of The Remote Employees And How Can They Counter It

    Algorithms are Black Boxes, That is Why We Need Explainable AI

  • |

    Linked: The count of managed service providers getting hit with ransomware mounts

    It’s hard not to agree with Sean’s takeaway, when your data is being hosted elsewhere, a lax security profile can have some serious effect on your business. One you can’t do anything about. “Organizations using full-service IT-managed service providers, such as Magnolia Pediatrics, are particularly at risk because the security of all of their systems…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)