DoLeads Integrator WordPress: security vulnerability
DoLeads Integrator WordPress
Security vulnerability in the DoLeads Integrator WordPress component. Threat level: Critical (CVSS 9).
Who is affected
This vulnerability affects: DoLeads Integrator WordPress. If you use this component on your site, check the version and update it as soon as possible.
How dangerous
Rating: Critical, CVSS 9 out of 10. Critical flaws are often exploited en masse within hours of disclosure.
What this flaw is
This is a security vulnerability in one of the site components. Full technical details are described in the source NVD entry, linked below.
Even seemingly lower-priority flaws are often chained into attacks, so it is not worth delaying the update of the vulnerable component.
Score breakdown (CVSS vector)
What the CVSS 9 rating means in practice:
- The attack can be carried out remotely, over the internet.
- No login or account required.
- Requires no action from the victim.
- The impact may reach beyond the vulnerable component itself.
- At risk: data confidentiality, integrity (data can be altered), site availability.
What to do
- Update the vulnerable component (DoLeads Integrator WordPress) to the latest version.
- If a patch is not out yet, temporarily disable the vulnerable element.
- Check whether the site has already been attacked: unusual files, new administrator accounts, redirects.
- Make a backup before you start making changes.
Does this flaw affect your site?
We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.
Request a free audit →