Security vulnerabilities in WPRemote (1)
-
Possible site takeover through stolen API credentials in combination with SQLi – (WPRemote <= 5.09)
Affected plugin WPRemote Active installs 20,000+ Vulnerable version <= 5.09 Audited version 5.09 Fully patched version 5.16 Recommended remediation Removal of the plugin Description This vulnerability is identical to this one in MalCare because MalCare and WPRemote share 99% of their codebase. Proof of concept Refer to this POC and use “wpremote” in step 4.…