Security vulnerabilities in BlogVault (1)
-
Possible site takeover through stolen API credentials in combination with SQLi – (BlogVault <= 5.09)
Affected plugin BlogVault Active installs 100,000+ Vulnerable version <= 5.09 Audited version 5.09 Fully patched version 5.16 Recommended remediation Removal of the plugin Description This vulnerability is identical to this one in MalCare because MalCare and Blogout share 99% of their codebase. Proof of concept Refer to this POC and use “bvbackup” in step 4.…