Pi-hole discloses data breach triggered by WordPress plugin flaw (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 04 Aug 12:16
https://sh.itjust.works/post/43413763

#cybersecurity

threaded - newest

limerod@reddthat.com on 04 Aug 14:54 collapse

Although GiveWP released a patch within hours of the vulnerability being reported on GitHub, Pi-hole criticized the plugin developer’s response, citing a 17.5-hour delay before notifying users and what it described as insufficient acknowledgment of the security flaw’s potential impact on donor names and email addresses.

Maybe, don’t depend so much on 3rd party plugins specially when handling sensitive data like names and email addresses.