WordPress Plugin Flaws Lead to Website Takeovers

TL;DR. Threat actors exploit vulnerabilities in Kirki and Burst Statistics WordPress plugins, enabling privilege escalation and full website compromise. - Kirki plugin versions 6.0.0 to 6.0.6 have an unauthenticated privilege escalation and account takeover flaw. - Burst Statistics plugin versions 3.4.0 to 3.4.1.1 are vulnerable to an authentication bypass.<

Sources

Back to QLANKR News