[Critical] CVE-2019-25738 – WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vuln...
Critical CVE-2019-25738 WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the...