A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site.
Edit config/nova.php and add the middleware to Nova's middleware stack. Place it after the standard Nova middleware so it can intercept responses and render the ...