[caption id="attachment_562" align="aligncenter" width="550"]
wysija MailPoet Wordpress Plugin[/caption] A famous security firm Sucuri has found a bug in the MailPoet WordPress plugin which has made more than 1,700,00 websites vulnerable to cyber attacks. Marc-Alexandre Montpas a researcher from the website security firm Sucuri has found this flaw few weeks ago and sent it to the MailPoet WordPress plugin developers.
How to hack WordPress website using MailPoet?
MailPoet plugin has a serious flaw that any unauthorized user can upload any file from the remote location. There is no authentication while you upload any file. This can allow the potential intruder to use your website for phishing lures, sending SPAMS and hosting malwares.
Is your Website Affected by MailPoet WordPress Plugin?
If you have downloaded and installed this MailPoet plugin in your WordPress then your website is vulnerable. More than 1,700,00 websites have downloaded this WordPress plugin. All the versions which are below 2.6.7 are vulnerable. The developers have released an update of it. You can download it and protect your WordPress website from hackers. [caption id="attachment_563" align="aligncenter" width="602"]
Wysija wordpress plugin vulnerabilities[/caption]
What is the MailPoet WordPress Plugin Flaw?
The WordPress Plugin developers have made a mistake in making the plugin. The developers assumed that admin_init will run only when administrator user visits the /wp-admin/ page. The developers have used admin_init() as an authentication method. This is easily passed away by the hacker.Tip for the Developers: Never use admin_init() as an authentication method while developing the Plugin.
How to protect your website from MailPoet WordPress Plugin?
- Firstly keep your plugin up to date.
- Use WordPress security plugins for the security
- First check the reviews of the plugins and then download it.
You might also like
[caption id="attachment_303" align="alignleft" width="150"]
Dominos website hacked[/caption] [caption id="attachment_332" align="alignleft" width="150"]
Evernote Forum site hacked[/caption]