Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

[caption id="attachment_562" align="aligncenter" width="550"]wysija MailPoet Wordpress Plugin wysija MailPoet Wordpress Plugin[/caption] A famous security firm Sucuri has found a bug in the MailPoet WordPress plugin which has made more than 1,700,00 websites vulnerable to cyber attacks. Marc-Alexandre Montpas a researcher from the website security firm Sucuri has found this flaw few weeks ago and sent it to the MailPoet WordPress plugin developers.

How to hack WordPress website using MailPoet?

MailPoet plugin has a serious flaw that any unauthorized user can upload any file from the remote location. There is no authentication while you upload any file. This can allow the potential intruder to use your website for phishing lures, sending SPAMS and hosting malwares.

Also SEE: Facebook uses its users news feed in a secret research experiment

Is your Website Affected by MailPoet WordPress Plugin?

If you have downloaded and installed this MailPoet plugin in your WordPress then your website is vulnerable. More than 1,700,00 websites have downloaded this WordPress plugin. All the versions which are below 2.6.7 are vulnerable. The developers have released an update of it. You can download it and protect your WordPress website from hackers. [caption id="attachment_563" align="aligncenter" width="602"]Wysija wordpress plugin vulnerabilities Wysija wordpress plugin vulnerabilities[/caption]

Also SEE: New Gmail API launched by Google with awesome features

What is the MailPoet WordPress Plugin Flaw?

The WordPress Plugin developers have made a mistake in making the plugin. The developers assumed that admin_init will run only when administrator user visits the /wp-admin/ page. The developers have used admin_init() as an authentication method. This is easily passed away by the hacker.Tip for the Developers: Never use admin_init() as an authentication method while developing the Plugin.

How to protect your website from MailPoet WordPress Plugin?

  • Firstly keep your plugin up to date.
  • Use WordPress security plugins for the security
  • First check the reviews of the plugins and then download it.

 

Is your website safe enough? Not sure? Contact us to have a penetration test of your website

You might also like

[caption id="attachment_303" align="alignleft" width="150"]Dominos website hacked Dominos website hacked[/caption] [caption id="attachment_332" align="alignleft" width="150"]Evernote Forum site hacked Evernote Forum site hacked[/caption]

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.