A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site.
A zero-day vulnerability in the ThemeREX Addons, a WordPress plugin installed on thousands of sites, is actively exploited by attackers to create user accounts with admin permissions and potentially ...