By Eduard Kovacs on July 15, 2014
A recently discovered vulnerability in WPtouch, a popular plugin that's used to create simple themes for the mobile visitors of WordPress websites, can be leveraged by an attacker to upload PHP files to impacted servers, Sucuri reported on Monday.
According to the security firm, an attacker can take control of WordPress websites by uploading PHP backdoors and other pieces of malware to the site's directories.
The flaw, which is located in the "core/classwptouchpro.php" file, can only be exploited on websites that allow guest users to register, Sucuri researchers said. In this classwptouchpro.php file, the admin_initialize() method is called by the "admin_init" hook, the use of which recently led to a file upload vulnerability in a different popular WordPress plugin.
SecurityWeek/ Full Read Here/ http://www.securityweek.com/security-vulnerability-found-popular-wptouch-wordpress-plugin
Reply
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.