News

After researchers were able to bypass a file upload validation flaw patch in WP Live Chat, a new patch has been issued.
The WordPress plugin is designed to allow users to upload files to a website admin. Each file is saved in a private directory, so each user can manage their own files after login.
The lack of proper file type and extension validation in the code allows for the upload of arbitrary files, posing a significant security risk. Read more on WordPress security: Backup Migration ...
WordPress File Manager plugin flaw causing website hijack exploited in the wild The critical vulnerability has been utilized in hundreds of thousands of attacks.
Hackers are exploiting a critical flaw affecting >350,000 WordPress sites Flaw is in File Manager, a plugin with more than 700,000 users; 52% are affected.