Undersatnding vulerability in 2.3.28
-
From the explanation at https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gigpress/gigpress-2328-authenticated-subscriber-sql-injection it makes it seem like only logged-in users can exploit the vulnerability.
This makes it possible for authenticated attackers with subscriber-level permissions and above to append
…
If new user account creation is disabled, and I’m the only authenticated user, this means that I can continue to use this plugin and not be worried about this particular exploit — can anyone confirm this understanding?
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Undersatnding vulerability in 2.3.28’ is closed to new replies.