Popular Crypto Plugin Suffers from Critical Security Vulnerability

February 9, 2024
1 min read

TLDR:

A critical security flaw has been identified in a popular WordPress plugin called “The Cryptocurrency Widgets – Price Ticker & Coins List.” The Cyber Security Agency of Singapore (CSA) has rated the vulnerability as a near-perfect 9.8 out of 10. The flaw is related to SQL Injection through the plugin’s ‘coinslist’ parameter, which could allow hackers to extract sensitive data or manipulate database queries without authorization.

According to the CVE Program, the vulnerability exists in versions 2.0 to 2.6.5 of the plugin. Cybersecurity experts have noted the issue of inadequate data handling by the plugin’s developer, Narinder-Singh. This incident highlights the broader security challenges faced by the cryptocurrency industry. Just weeks ago, Bitcoin ATM manufacturer Lamassu Industries patched a critical vulnerability that risked giving attackers control over its machines.

The incident underscores the importance of robust cybersecurity measures to protect users and their assets in the growing cryptocurrency industry.

(400 words)

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat