Update older versions of MailPoet/WYSIJA right away!
-
I just came across this article on ArsTechnica about a major security issue with MailPoet.
The bug allows attackers to remotely upload any file of their choice to vulnerable servers. Cid declined to provide specifics about the flaw other than to say it’s the result of the mistaken assumption that WordPress admin_init hooks are called only when a user with administrator privileges visits a page inside the /wp-admin directory. In fact, “any call to /wp-admin/admin-post.php also executes this hook without requiring the user to be authenticated.” The behavior makes it possible for anyone to upload files on vulnerable sites. The only safe version is the just released 2.6.7, which should be installed immediately on all vulnerable websites. MailPoet gives sites added abilities to create newsletters and automatically post notifications and responses.
This is a major security implication for any site running MailPoet/WYSIJA, so be sure to update right away. I’m a bit upset about this because I paid for the premium version of MailPoet and never received any kind of notice from them about this vulnerability.
- The topic ‘Update older versions of MailPoet/WYSIJA right away!’ is closed to new replies.