Hackers are creating backdoor accounts and cookie files on WordPress sites running OneTone

[ad_1]

the-creative-exchange-zs3ofu40cqu-unsplash.jpg

Image via The Creative Exchange

Hackers are actively targeting WordPress sites running the OneTone theme to exploit a vulnerability that allows them to read and write site cookies and create backdoor admin accounts.

The campaign has been going since the start of the month, and it’s still underway.

The vulnerability is a cross-site scripting (XSS) bug in OneTone, a popular but now…

[ad_2]
More Info

About mblog.my

Check Also

Adding Images From Your Phone With Ease – WordPress.com News

Adding Images From Your Phone With Ease – WordPress.com News

[ad_1] We’re excited to share a new feature in the desktop editor and Jetpack mobile …