The latest exploitation wave around two WordPress plugins shows how a small access-control flaw can turn ordinary site extensions into a path toward privilege escalation and site takeover.
A flaw in Burst Statistics could let attackers sidestep authentication on more than 200,000 WordPress sites, turning a routine analytics tool into a privilege-escalation risk.
A flaw in a popular analytics plugin shows how a single authentication mistake can turn ordinary site tooling into a privilege-escalation route.