WordPress plugin Mailpress high-risk remote command execution vulnerability

Vulnerability description:
Mailpress is a popular WordPress mail plugin. Due to unauthorized calls, certain methods of the system can be called without logging in, causing remote command execution.
Insert picture description here

Affected version: all versions, the latest version 5.4.3

Vulnerability level: high risk

Repair suggestions:
1. It is recommended to disable this plug-in.
2. Add a website to the cloud observation, and learn about sudden/0day vulnerabilities in website components in time. (Source: Guo Shenghua Blog of Oriental Alliance)

Guess you like

Origin blog.csdn.net/weixin_45715145/article/details/102368754