Vulnerability Bulletins

Severe Flaws Patched in Responsive Ready Sites Importer Plugin


System information

   
Affected software Wordpress

Description

https://www.wordfence.com/blog/2020/03/severe-flaws-patched-in-responsive-ready-sites-importer-plugin/ On March 2nd, our Threat Intelligence team discovered several vulnerable endpoints in Responsive Ready Sites Importer, a WordPress plugin installed on over 40,000 sites. These flaws allowed any authenticated user, regardless of privilege level, the ability to execute various AJAX actions that could reset site data, inject malicious JavaScript in pages, modify theme customizer […]

More info:

https://www.wordfence.com/blog/2020/03/severe-flaws-patched-in-responsive-ready-sites-importer-plugin/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2020-03-20
Ministerio de Defensa
CNI
CCN
CCN-CERT