Varios plugins de wordpress vulnerables

  • Autor Autor propa
  • Fecha de inicio Fecha de inicio
propa

propa

1
Zeta
Verificación en dos pasos activada
Suscripción a IA
Hola, les dejo el mensaje que me ha llegado de parte de Sucuri Security

Multiple WordPress Plugin Security Vulnerabilities

This is a Public Service Announcement, it does not mean you are affected. It is being shared to help bring awareness to a vulnerability that affects multiple WordPress plugins. If you do use these plugins or know someone that uses them, please help spread the word.

In a coordinated effort with our partners at Yoast, we have worked together to identify a security vulnerability in multiple WordPress plugins including some of the top plugins in the repository:

Jetpack
WordPress SEO
All in one SEO
UpDraft Plus
iThemes Exchange
and many more

The crux of the problem comes in the way that the add_query_arg() and remove_query_arg() functions were being employed. Through coordinated collaboration with the various developers and the WordPress security team we have been able to organize the public disclosure of this release.

Saludos
 
Justo salieron las actualizaciones para los dos primeros plugins...
 
Gracias por avisar, el by Yoast al actualizarlo me duplicó el <script type='application/ld+json'>{"@context":"http:\/\/schema.org",
 
Actualizados :encouragement: gracias por la info.
 
Gracias por la info, debemos de actualizar inmediatamente, saludos.
 
Atrás
Arriba