• About Us
  • Contact Us
  • Advertise
  • Privacy Policy
No Result
View All Result
Digital Phablet
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
No Result
View All Result
Digital Phablet
No Result
View All Result

Home Technology wpDiscuz WordPress Plugin Puts Thousands of Websites at Risk

wpDiscuz WordPress Plugin Puts Thousands of Websites at Risk

DP Staff by DP Staff
July 30, 2020
in Technology
Reading Time: 1 min read
A A
ADVERTISEMENT

A security flow found in the wpDiscuz’s WordPress plugin which can allow hackers to inject malicious code easily on any website.

This vulnerability was first identified by security experts at Wordfence, who further confirms that with this flaw, hackers will also be able to execute PHP files and upload arbitrary files to the website where this plugin is installed.

wpDiscuz provides an alternative to the commenting system to WordPress, just like jetpack comments, Disqus, or any other famous commenting plugin.

ADVERTISEMENT

This security flaw was first identified by Wordfence and had asked wpDiscuz to fix it, for that after a few days, the devs said they had fixed it. But later, in the latest update of the WordPress plugin, this issue was once again found to which wordfence took notice and told, the patch was unable to fix the security flaw as of now.

The issue was found in version 7 of the WordPress plugin, in the feature which allows users to upload images to the comments. The system is unable to detect if the file extension is of an image or malicious code.

As of now the best thing for the web developers who are using wpDiscuz is to move away from it if the plugin is not getting a patch within 24 hours, keeping the plugin would allow hackers to hack your sites and all the other sites associated with that host to be at the risk of hacking.

Tags: PrivacyWordpress
ADVERTISEMENT
DP Staff

DP Staff

Related Posts

WhatsApp Introduces Anti-Leak Chat Feature You Should Enable Now
News

WhatsApp Introduces Anti-Leak Chat Feature You Should Enable Now

April 24, 2025
US Analyzes Housing Data to Target Migrants for Trump's Deportation
News

US Analyzes Housing Data to Target Migrants for Trump’s Deportation

April 16, 2025
WhatsApp Tests New Chat Feature for Improved Privacy
News

WhatsApp Tests New Chat Feature for Improved Privacy

April 8, 2025
Meta's Censored "Facebook For China" Seems Like A Privacy Risk
News

Meta’s Censored “Facebook For China” Seems Like A Privacy Risk

March 10, 2025
Next Post

Use Mac OS Emulator on Your Windows PC, Best Way To Run Mac on PC

  • About Us
  • Contact Us
  • Advertise
  • Privacy Policy

© 2025 Digital Phablet

No Result
View All Result
  • Home
  • News
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones

© 2025 Digital Phablet