ZeroHour
Infosecurity Magazinepublished ()ingested

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

highVulnerabilityimportance 55
AI summary · glm-5.3-flash

A critical unauthenticated flaw in the User Profile Builder WordPress plugin exposed roughly 40,000 sites to administrator account takeover.

Infosecurity Magazine reports a critical flaw in the User Profile Builder WordPress plugin that let unauthenticated attackers access administrator accounts. Approximately 40,000 sites were exposed to full admin takeover as a result. The report did not specify a CVE identifier or state whether exploitation was observed in the wild.

  • Unauthenticated attackers could gain access to administrator accounts via the plugin flaw
  • About 40,000 WordPress sites were exposed to takeover
  • No CVE id or confirmed exploitation details provided in the coverage
Full article

Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

This source does not provide full text. Read it at infosecurity-magazine.com.