Episode 91: How Hackers Can Use CSRF Vulnerabilities and Spearphishing to Wreak Havoc on WordPress




Think Like a Hacker with Wordfence show

Summary: This week, we chat about the CSRF vulnerability found in the Child Theme Creator by Orbisius and how attackers could use a vulnerability like this with spearphishing to wreak havoc, much like the phishing campaigns now being found on the Canva design platform. We discuss the benefits of adding application passwords for REST API authentication planned for WordPress version 5.6, and the ramifications of the critical, wormable RCE bug patched by Microsoft.