Paid WordPress users beware – worrying security flaw puts accounts and info at risk




  • An improper neutralization flaw was found in the WordPress Paid Membership Subscriptions plugin
  • This plugin is used by more than 10,000 sites, enabling memberships and paying user accounts
  • A patch is now available, so users should update immediately

A high-severity vulnerability has been discovered in a popular premium WordPress plugin, allowing threat actors to access, or exfiltrate, sensitive data without authentication.

Security researcher ChuongVN from the Patchstack Alliance recently found an “improper neutralization of special elements used in an SQL command” flaw, affecting the WordPress Paid Membership Subscriptions plugin.

https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img