Saijo George

Curated by Saijo George

Read more

tuesday11 Feb 2020

Authentication Vulnerability with WordPress Plugin Profile Builder < 3.1.1

https://wordpress.org

Profile Builder and Profile Builder Pro were affected by a broken authentication vulnerability, allowing unauthenticated users to register or edit their account and gain the Administrator role using the plugin’s forms. The free version of the plugin has over 50,000+ active installations.

The issue has been fixed in version 3.1.1. The vulnerability exists in the Plugin’s own generated Registration Form or Profile Edit Form, this means if the site is using the shortcode [wppb-register] or [wppb-edit-profile] then it is vulnerable. It’s highly recommended you update it if you have an older version.

General


I love tl;dr Marketing because I can get all the latest SEO news and trends in one spot without having to read lengthy articles. I really look forward to the daily emails to see what's new in our industry!

Stricter Field Validation Implemented for Doubleclick Bid Manager API 1 - Paid Media News

Ryan Mews SEO Manager Merkle