While cleaning-up a hacked WordPress site, we found that some malicious code was added to the theme by its developers.
Twenty five plugins for WordPress were found to be vulnerable to cross-site request forgery (CSRF) attacks.
With a proof of concept and a video, we explain in this post how hackers exploit XSS vulnerabilities in order to create administrator accounts on your blog.
Critical zero-day vulnerability fixed in WordPress File Manager (700,000+ installations). Update immediately.