WordPress plugin vulnerability enables hackers inject malicious code

WordPress plugin vulnerability enables hackers inject malicious code

A WordPress plugin that enables websites to create and deploy popups has been discovered to contain flaws that allow hackers to inject malicious JavaScript code into such popups. The bugs, which affect all versions up to and including Popup Builder 3.63, lets attackers steal information and take over websites, said a blog post by Defiant QA engineer Ram Gall. 

One vulnerability allowed an unauthenticated attacker inject malicious JavaScript into any published popup, which would then be executed whenever the popup loaded. The other vulnerability allowed any logged-in user, even those with minimal permissions such as a subscriber, to export a list of all newsletter subscribers, export system configuration information, and grant themselves access to various features of the plugin,” he said.

By Rene Millman

To read the full article, please click here.

Facebooktwittergoogle_plusredditlinkedinmail