Web Hack List

Collected research

Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)

The WordPress MailPoet plugin assumed the admin_init hook only fires for logged-in administrators, but any request to admin-post.php runs it too. That left the theme upload path reachable without authentication, so anyone could upload an arbitrary PHP file to the site and execute code on it.

Record

Published by
Sucuri Blog
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sucuri Blog, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .