Over 150k WordPress sites at takeover risk via vulnerable plugin
ID: 53ae6dd7-9ffa-5b04-a576-6ecad02c0a9f
STIX ID: report--53ae6dd7-9ffa-5b04-a576-6ecad02c0a9f
Feed Name: Bleeping Computer
Threat Score
Two vulnerabilities in the POST SMTP Mailer WordPress plugin (CVE-2023-6875: unauthenticated authorization bypass via type-juggling; CVE-2023-7027: stored XSS) affected versions up to 2.8.7 and could allow full site takeover. Wordfence reported the issues and the vendor released a patched 2.8.8 on 2024-01-01; roughly 150,000 sites are estimated to remain vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
