• Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+
Precise Online ManagementPrecise Online Management
  • Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+

Flaw in WordPress core remains unpatched since November

WordPress

Flaw in WordPress core remains unpatched since November

June 29, 2018 News, Security

News Courtesy of bleepingcomputer.com:

Security researchers from RIPS disclosed today details about an unpatched security flaw impacting WordPress, the Internet’s most popular content management system (CMS).

RIPS researchers say they have told the WordPress team about this particular vulnerability in November last year, but the WordPress devs have failed to release a patch.

The vulnerability affects the core of the WordPress CMS, and not one of its plugins or themes. More precisely, the bug was found in the PHP functions that deletes thumbnails for images uploaded on a WordPress site.

They can hijack sites because the vulnerability allows attackers to delete wp-config.php, which is a site’s config file. Attackers who delete this file can re-initiate the installation process and install the site using their own database settings, effectively hijacking the site to deliver custom or malicious content.

– Read Source Article

Ryan’s Take

If it weren’t for the fact that “Author” privileges are needed for this attack, this bug would be huge. Usually, the WordPress team are very quick to correct flaws that have been pointed out to them. It’s hard to believe that this particular flaw has not been fixed since it was first discovered in November.

I don’t think any reputable WordPress site would allow a user to register right off the bat as an Author. As the source article mentions, if they can somehow elevate their account status then it would open the door for a website takeover. In my opinion, unless you are running some kind of forum website you should disable new registrations completely. It’s also a good idea to have a security plugin installed on your site. I highly suggest All In One WP Security & Firewall. It offers a lot of different protections against attacks.

0 0 votes
Article Rating
Tags: SecurityUnpatchedwordpress
Share
0

About Ryan Faucher

Owner-operator of Precise Online Management. I also manage Kettlebell Krusher, a website dedicated to all things kettlebell as well a blog for my weight loss progress.

Subscribe
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments

Categories

  • News
  • Niche Dreams
  • Reviews
  • Security
  • SEO
  • Tips

Recent Posts

  • 9 Benefits of Social Media for Your Organization
  • Advantages of Having Marketing Research Samples
  • Link Building Services: How To Find A Trustworthy Provider
  • SAS Affiliate Review and Tips for Affiliate Marketers
  • Comparison Of The Best Link Indexing Service Features & Benefits

Archives

  • January 2022
  • January 2021
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
Ready to get started? Pick and choose your website and / or SEO services Order Services

© 2025 · Precise Online Management, LLC.
This site is owned and operated by Ryan Faucher

  • Visit Us on Facebook
  • Visit Us On Google+
Prev Next
wpDiscuz
X
WEB DESIGN SPECIAL PRICING - Over 60% off design packages through Fiverr
See Details