More

    WordPress users beware – these popular theme plugins have some major security issues




    • Patchstack found two bugs in a WordPress theme and a plugin from InspiryThemes
    • The bugs were not addressed in three latest versions
    • Users are advised to disable the products or limit new account creation

    A popular WordPress theme and plugin have been found carrying vulnerabilities that allow malicious actors to elevate their privileges to admin.

    WordPress security researchers Patchstack revealed the theme and plugin in question are called RealHomes and Easy Real Estate, both designed by InspiryThemes, and designed to be used in the real estate industry. The vulnerabilities are tracked as CVE-2024-32444, and CVE-2024-32555, and both have a severity score of 9.8/10 – critical. Both flaws allow malicious actors to elevate their privileges to admin, gaining full control of the WordPress site, and allowing them to install, delete, or modify plugins, tamper with the content, exfiltrate sensitive data, and more.

    https://cdn.mos.cms.futurecdn.net/ebZTsHB4jGup8yK4ebtwyR-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img