WordPress security flaws: 800,000 sites running NextGen Gallery plugin potentially vulnerable to pwnage

[ad_1]

Unpatched sites could get pwned – but admins must fall for social engineering

WordPress security flaws: 800,000 sites running NextGen Gallery plugin potentially vulnerable to takeover

Users of NextGEN Gallery, the image management plugin for WordPress, have been urged to update their websites after the discovery of serious cross-site request forgery (CSRF) vulnerabilities.

The most serious of two flaws found by security researchers – each residing in separate functions – could lead to remote code execution (RCE) and stored cross-site scripting (XSS).

As a result, attackers could take control of a website, inject it with spam links, or redirect…

[ad_2]
More Info

About mblog.my

Check Also

Adding Images From Your Phone With Ease – WordPress.com News

Adding Images From Your Phone With Ease – WordPress.com News

[ad_1] We’re excited to share a new feature in the desktop editor and Jetpack mobile …

Leave a Reply

Your email address will not be published. Required fields are marked *