SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites

https://www.bleepingcomputer.com/news/security/sqli-flaw-in-elementor-ally-plugin-impacts-250k-plus-wordpress-sites/

An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication.

18 points · 1 comments · view on lemmy.world

1 Comments

MonkderVierte@lemmy.zip · 1 pts · 166d

Eh, the usual critical Wordpress plugin vuln.

Please, guys; if you don't write a blog, use any other framework matching your usecase. Wordpress plugins are no good.