Sunday, August 1, 2021
Hindi News
Subscribe Us
Upload News
  • About
  • Subscribe Premium
  • Contcat Us
21 °c
Delhi
18 ° Fri
17 ° Sat
15 ° Sun
15 ° Mon
Press24 News English
No Result
View All Result
  • Login
  • Register
  • Home
  • Top News
  • Politics
  • National
  • World
  • Business
  • Entertainment
  • Lifestyle
    • Travel
    • Health
    • Fashion
    • Food
  • Tech
    • Science
  • Sports News
  • Opinion
Press24 News English
No Result
View All Result
No Result
View All Result
Press24 News English
Home Tech

Attn Website Owners! WordPress Found To Have These Vulnerabilities: Here’s How To Fix

Press24 News by Press24 News
August 1, 2021
in Tech
198 13
0
285
SHARES
468
VIEWS
Share on WhatsappShare on TwitterShare on Facebook

READ ALSO

Booking of Bajaj Chetak electric scooter now resumed in these two cities, runs 95 km on a single charge

Microsoft launches first beta version of Windows 11: Check how to install on your laptop or PC | Technology News

Website owners who use WordPress are advised to update to the latest version immediately.

The vulnerabilities were found by The Wordfence Threat Intelligence team and pertain to the attacker achieving authenticated directory traversal.

WordPress is the backend to many websites across the world. It has been found that one WordPress plugin that was installed on over 1,00,000 websites has two separate vulnerabilities. The plugin, called WordPress Download Manager is used to change how dowload pages are displayed. The vulnerabilities were found by The Wordfence Threat Intelligence team and pertain to the attacker achieving authenticated directory traversal. Now, the WordPress Download Manager has some protections in place to protect against directory traversal, they did not prove to be sufficient in this particular case.

As a result, it was possible for a contributor with lower provileges to retreive contents of a site’s wp-config.php file by adding a new download and performing a directory traversal attack. Here, the contents of teh wp-config.php were visible in the page’s source code upon previewing the download. Since the contents of the file were echoed out onto the page source, a user with author-level access could also upload a file or multimedia containing malicious JavaScript and set the contents of the file to the path of the uploaded file which could result in Stores Cross-Site Scripting.

Before this, the WordPress Download Manager team had patched a vulnerability that allowed users to upload files with php4 extensions as well as other potentially malicious files. Although this patch protected many configurations, it only checked the last file extension that made it possible for an attacker to carry out a “double extension” attack by uploading a file with multiple extensions like info.php.png.

The Wordfence Threat Intelligence Team had disclosed its findings to the WordPress team in May and the developers released a patch the following day. Website owners who use WordPress are advised to update to the latest version immediately.

Read all the Latest News, Breaking News and Coronavirus News here


Disclaimer: This post has been auto-published from an agency/news feed without any modifications to the text and has not been reviewed by an editor.

Source link

Tags: AttnfixHeresOwnerstech newstechnologyVulnerabilitieswebsiteWordPress
SendTweet71Share114Share29

Related Posts

Tech

Booking of Bajaj Chetak electric scooter now resumed in these two cities, runs 95 km on a single charge

August 1, 2021
Tech

Microsoft launches first beta version of Windows 11: Check how to install on your laptop or PC | Technology News

August 1, 2021
Tech

Swimply lets you swim in a stranger’s pool. It’s less weird than you think

August 1, 2021
Tech

Twitter Launches Bounty Program To Find Biases In Its Image-Cropping Algorithm

August 1, 2021
Tech

Nokia T20 tablet will come with 10.36 inch display, specifications and price leaked online

August 1, 2021
Tech

Facebook plans to launch its augmented reality Ray-Ban smart glasses soon | Technology News

July 31, 2021
No Result
View All Result

Recent Posts

  • Corona In The World, Danger Of Fourth Wave In Canada
  • Attn Website Owners! WordPress Found To Have These Vulnerabilities: Here’s How To Fix
  • Yamuna Water Level Recedes Below Danger Mark in Delhi
  • Assaults on police in England and Wales rise above 100 a day during pandemic | Police
  • Hopes of healthy Q1 results may push Indian equities higher next week

Recent Comments

    Press24 News

    सच का साहस

    Press24News is venture of Kotgari News & Media Network (KNMN). Kotgari News Network working as news & media agency across India & abroad

    सच का साहस

    Categories

    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • National
    • Opinion
    • Politics
    • Science
    • Sports News
    • Tech
    • Top News
    • Travel
    • Uncategorized
    • World

    Recent Posts

    • Corona In The World, Danger Of Fourth Wave In Canada
    • Attn Website Owners! WordPress Found To Have These Vulnerabilities: Here’s How To Fix
    • Yamuna Water Level Recedes Below Danger Mark in Delhi
    • Assaults on police in England and Wales rise above 100 a day during pandemic | Police

    Follow Us

    Facebook Youtube Twitter Line
    • T & C Legal Disclaimer
    • Privacy Policy
    • Subscriber Agreement and Terms of Use
    • Refund Cancellation Policy
    • FAQ

    © 2021 Press24 News English - Kotgari News & Media Network Press24 News.Traffic Bot

    • Login
    • Sign Up
    • Cart
    No Result
    View All Result
    • Home
    • Top News
    • Politics
    • National
    • Business
    • World
    • Entertainment
    • Lifestyle
      • Fashion
      • Health
      • Food
      • Travel
    • Sports News
    • Tech
    • Science
    • Hindi News
    • Premium Access
    • Opinion

    © 2021 Press24 News English - Kotgari News & Media Network Press24 News.Traffic Bot

    Welcome Back!

    Sign In with Google
    OR

    Login to your account below

    Forgotten Password? Sign Up

    Create New Account!

    Sign Up with Google
    OR

    Fill the forms below to register

    This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
    Are you sure want to unlock this post?
    Unlock left : 0
    Are you sure want to cancel subscription?