Vulnerable Plugin Exploited in Spam Redirect Campaign (blog.sucuri.net)
Some weeks ago a critical unauthenticated privilege escalation vulnerability was discovered in old, unpatched versions of the wp-user-avatar plugin. It also allows for arbitrary file uploads, which is where we[…]