Telecom Tidbits
Jared's Network and Security Blog
  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links

WordPress and Joomla Updates

July 7, 2017 Jared Hall General, WordPress

ScreenShot283

  1. There were two bugs discovered and fixed in the popular WordPress “WP Statistics” plugin.  The first one is a SQL Injection vulnerability that could be exploited by a local, low-privileged user, like a “Subscriber” account.  A SQL Injection attack could allow that subscriber to be able to add an “Administrator” account.
  2. About the time that this bug was fixed, a Cross-Site Scripting (XSS) vulnerability was  detected in that same WP Statistics plugin, and also fixed.  If you use this plugin,  make sure you update it right away.
  3. A Cross-Site Scripting (XSS) bug was also found in the “All-in-One WP Migration” plugin. This has been corrected.  Please update this plugin if it has been installed.
  4. A reflected Cross-Site Scripting (XSS) vulnerability was found with the “WP Download Manager” plugin.  This has been fixed.  Please update this plugin if you’ve installed it.

ScreenShot285

  1. A new Joomla security update is available which fixes two XSS vulnerabilities and an information disclosure vulnerability.

 

 

« Android Users Rejoice! » The Six Phases of a Project or Upgrade

Tools & Downloads

Download Center

Categories

Good Reads (PDF)

Recent Posts

  • PayPal Woes and Degenerative AI
  • A Pathetic Defense of Julian Assange
  • Damned if you do. Damned if you don’t.
  • ProtonMail? Not Worth an Electron!
  • Give it a REST: Serious WordPress Bugs
$
Select Payment Method
Personal Info

Donation Total: $20.00

↑

  • Home
  • Telecom Corner
  • About
  • Contact
  • Donate
  • Site Index
  • Links
Temporal Based Intelligence © 2017