Severe vulnerability exposes WordPress websites to attack

  • 16 August 2018
  • 0 replies
  • 128 views

Userlevel 7
Badge +54
Researchers say the PHP security flaw could leave countless WordPress websites open to exploit.
 By Charlie Osborne | August 16, 2018
 
A severe WordPress vulnerability which has been left a year without being patched has the potential to disrupt countless websites running the CMS, researchers claim.
 At the BSides technical cybersecurity conference in Manchester on Thursday, Secarma researcher Sam Thomas said the bug permits attackers to exploit the WordPress PHP framework, resulting in a full system compromise.
 
If the domain permits the upload of files, such as image formats, attackers can upload a crafted thumbnail file in order to trigger a file operation through the "phar://" stream wrapper.
 
Full Article.

0 replies

Be the first to reply!

Reply