Critical security vulnerability found in Convert Plus plugin

3rd June 2019

For the second time in the last 2 weeks, a popular WordPress plugin has been discovered to contain a critical security vulnerbility, allowing hackers to extend admin control permissions in WordPress.

The plugin is Convert Plus, and it is currently active installed in over 100,000 WP sites, is a business lead tool containing a “unauthenticated admin creation” issue. If the attackers can gain access, it could allow them to create new WordPress users with different user roles up to administrator, giving them full access to the site including deleting other users, deleting content, injecting scripts into the themes or plugins and much more.

Those using the Convert Plus plugin on version 3.4.2 have to quickly update to version 3.4.3 to patch the vulnerability as soon as possible to avoid potential hacking of the site and the site’s hosting server.

The vulnerability was found on 24 May and an update patch was released on the 28 May.

Last week, security analysts found another vulnerbility hole within the WordPress plugin, Slick Popup.


4th November 2019

WordPress Maintenance for eCommerce websites

26th June 2019

10 Reasons Why You Need WordPress Maintenance

28th May 2019

We’re pleased to announce the launch of our new website