Uninvited Party Crasher: PKP-WAL Plugin’s Nefarious Intentions

A seemingly innocent import/export plugin, PKP-WAL, has been found to harbor a remote code execution vulnerability. If you’re a Journal Editor or Production Editor user, it’s time to upgrade to version 3.4.0-4 or later to avoid this unwelcome guest.

Hot Take:

Yikes! Who knew that a friendly cover image could harbor such nefarious intentions? It seems PKP-WAL, the unassuming import/export plugin, has been playing host to a path-traversing, PHP-code-executing party crasher. If you're a Journal Editor or Production Editor user, it's time to upgrade your party invites to version 3.4.0-4 or later, unless you fancy your files being overwritten by this unwelcome guest.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here