This popular WordPress security plugin has a worrying flaw which exposed user data



  • WordPress plugin flaw let low-privileged users access sensitive server files and credentials
  • CVE-2025-11705 affects plugin versions 4.23.81 and earlier; patch released October 15
  • About 50,000 sites remain vulnerable; admins urged to update immediately

A popular WordPress plugin with more than 100,000 active installations carried a bug that allowed threat actors to read any file on the server – including people’s emails and in some cases, passwords, too.

Security researchers at Wordfence reported a vulnerability in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress. As the name suggests, this plugin allows site owners to scan for malware, protect their sites against brute-force attacks, defend against known flaws, and more.


https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img