Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

2 million sites are affected, WordPress plug-in ACF is exposed high-risk vulnerabilities

2025-01-15 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > IT Information >

Share

Shulou(Shulou.com)11/24 Report--

CTOnews.com May 10 news, Advanced Custom Fields (ACF) is a frequently used WordPress plug-in, has been installed in more than 2 million sites around the world, recently exposed that the plug-in has a high-risk vulnerability of XSS (cross-site scripting).

This XSS vulnerability in ACF allows unauthorized users to potentially steal sensitive information without the permission of the webmaster.

Malicious actors may exploit vulnerabilities in plug-ins to inject malicious scripts, such as redirects, advertisements, and other HTML payloads. If a user visits a tampered site, the user's device will be infected and execute a malicious script.

At present, officials have released an update of version 6.16 to fix the above vulnerabilities. If a webmaster is still using version 6.15 or earlier, CTOnews.com recommends upgrading as soon as possible.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

IT Information

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report