WordPress backup plugin flaw exposes millions of sites to takeover attacks
A critical SQL injection vulnerability in a widely-used WordPress backup plugin allows unauthenticated attackers to execute arbitrary code and fully compromise affected websites. Administrators should update immediately.
Why this matters
A critical SQL injection vulnerability in a widely-used WordPress backup plugin allows unauthenticated attackers to execute arbitrary code and fully compromise affected websites. Administrators should update immediately.
Check the original work
This explanation is Korpalis’s guide to the material, not a replacement for it. Read the publisher’s page for the full method, evidence and limitations.