Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
WordPress’s cryptocurrency gadget plugin has a serious vulnerability that risks leaking sensitive information

WordPress’s cryptocurrency gadget plugin has a serious vulnerability that risks leaking sensitive information

CointimeCointime2024/02/08 07:33
By:Cointime

On February 8th, the Cyber Security Agency of Singapore (CSA) emphasized that the cryptocurrency widget plugin "Cryptocurrency Widgets - Price Ticker Coins List" for the web development platform WordPress contains a serious vulnerability that can be used to extract sensitive information. According to the security company CVE Program, the plugin was provided by a supplier named "narinder-singh", and versions 2.0 to 2.6.5 were found to carry this vulnerability.

The aforementioned vulnerability allows unauthorized attackers to append additional SQL queries to existing queries, thereby extracting sensitive information from the database. The security advisory issued by the Singaporean Cyber Emergency Response Team (SingCERT) rates this plugin vulnerability at 9.8/10, which is classified as "critical". (Cointelegraph)

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Core Scientific Nets $580M in Q1 Despite Revenue Miss, Eyes AI and HPC Future

Nasdaq-listed Bitcoin miner Core Scientific Inc. has reported a net income of $580 million for the first quarter of 2025, more than double the $210 million recorded during the same period last year. However, the firm fell short of analyst expectations for revenue, signalling the growing impact of industry shifts and operational transformation.

DeFi Planet2025/05/09 12:00
Core Scientific Nets $580M in Q1 Despite Revenue Miss, Eyes AI and HPC Future