High Severity Vulnerability Patched in WordPress Download Manager Plugin Installed On 100,000 Websites – Tech Business News

[ad_1]

On July 8, 2022 the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability discovered in “Download Manager,” a WordPress plugin that is installed on over 100,000 sites.

This flaw makes it possible for an authenticated attacker to delete arbitrary files hosted on the server, provided they have access to create downloads.

If an attacker deletes the wp-config.php file they can gain administrative privileges, including the ability to execute code, by re-running the WordPress install process.

Wordfence Premium, Wordfence Care, and Wordfence…

[ad_2]
More Info

About mblog.my

Check Also

Adding Images From Your Phone With Ease – WordPress.com News

Adding Images From Your Phone With Ease – WordPress.com News

[ad_1] We’re excited to share a new feature in the desktop editor and Jetpack mobile …

Leave a Reply

Your email address will not be published. Required fields are marked *