••••••••••••••••••••
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence
IT Security Downloads

IT Security Downloads

🚨
dplugins • CVE-2026-14378
CVE-2026-14378 | The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_use
Advisory ansehen ➔
LIVE …
Keine Beiträge in dieser Ansicht

Wähle einen anderen Filter oder setze die Filter zurück, um alle aktuellen Meldungen anzuzeigen.

️ Threat Hunter Status-Update verfassen
Community Stream
News-Deck IT Security Downloads 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting

0 Artikel gemerkt
Keine gemerkten Artikel vorhanden.
Klicke auf 🔖 an einer Nachricht, um sie hinzuzufügen.
GLOBAL CTI GEO-RADAR
LIVE VECTOR
APT29 / SandwormVolt TyphoonLazarus GroupCharming KittenKRITIS Target ZoneScattered Spider
DIFF: