[ad_1]
On July 8, 2022 the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability discovered in “Download Manager,” a WordPress plugin that is installed on over 100,000 sites.
This flaw makes it possible for an authenticated attacker to delete arbitrary files hosted on the server, provided they have access to create downloads.
If an attacker deletes the wp-config.php file they can gain administrative privileges, including the ability to execute code, by re-running the WordPress install process.
Wordfence Premium, Wordfence Care, and Wordfence…
[ad_2]More Info