Collected research
Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)
The WordPress MailPoet plugin assumed the admin_init hook only fires for logged-in administrators, but any request to admin-post.php runs it too. That left the theme upload path reachable without authentication, so anyone could upload an arbitrary PHP file to the site and execute code on it.
Record
- Published by
- Sucuri Blog
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sucuri Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .