Skip to main content Skip to navigation

IT Security Service

IT Services - Information Security


Contacts

Mail: CSIIRT@warwick.ac.uk
Phone: ext 73737 (Helpdesk)
PGP key
RFC 2350

Security Alerts

2024-05-01 - WordPress-ValvePress-Automatic-Plugin - CVE-2024-27956

CRITICAL - Warwick CSIIRT has been notified that a vulnerability in the ValvePress Automatic plugin for WordPress could allow a threat actor to perform SQL injection (SQLi). In the attacks observed so far, the vulnerability is used to run unauthorised database queries and create new admin accounts on susceptible WordPress sites, which could then be leveraged for follow-on post-exploitation actions.

Service Description

The ITS Security Team provides a comprehensive IT Security service to The University of Warwick for users, groups and the many electronic systems.

Mail: CSIIRT@warwick.ac.uk
Phone: ext 73737 (Helpdesk)
PGP key
RFC 2350