• A flaw in TI WooCommerce Wishlist allows threat actors to upload arbitrary files
  • Since the files can be malicious, they could fully take over a website
  • A patch is not yet released, so users should take care

A critical-severity vulnerability in a popular WordPress plugin is possibly exposing hundreds of thousands of websites to different risks, including complete website takeover.

Security researchers from Patchstack have claimed TI WooCommerce Wishlist carried an arbitrary file upload flaw, which allowed actors to upload malicious files to the underlying server without authentication.



Source link

Podcast also available on PocketCasts, SoundCloud, Spotify, Google Podcasts, Apple Podcasts, and RSS.