PHPMailer Critical Vulnerability affects millions of websites
One of the core capabilities of WordPress is the ability to send mail to subscribers using a code library called PHPMailer. Today, a critical vulnerability was discovered in the PHPMailer library. A proof of concept has been published that details how hackers may take over complete control of your WordPress website using this vulnerability.
While it is expected that WordPress will issue an update in short order to correct this issue, there is, nevertheless, an opportunity for this vulnerability to be exploited before the fix is released. Also, since the PHPMailer library is a commonly used building block in many websites (not just WordPress), there is also a likelihood that an exploit will be developed unless all websites that use this library are updated.
For those seeking further information, an in-depth analysis of this issue is presented on the WordFence Security Blog.
Recommended Corrective Actions
If you are a programmer and can make the required changes to your WordPress (or other) websites, I recommend you follow the instructions detailed in the blog post above. Otherwise, keep an eye out for the next WordPress security update and ensure you apply it immediately.
If you require assistance implementing this fix, please contact your web designer. If you don’t have a web designer, you may contact me.
Jack Eisenberg is the owner of Safe and Secure Computing Windsor, Ontario.

