Update now! Hackers are actively taking advantage of zero day vulnerabilities in multiple WordPress plug-ins. WordPress Q&A reward plug-in

One year ago (2023-11-30) Chief Editor
6 minutes
two hundred and sixty-seven
zero

Message from webmaster's home (ChinaZ. com) on March 2: So far, WordPress is the most widely used website building technology on the Internet. According to recent statistics, more than 35% of Internet websites use WordPress CMS (content management system).

Because WordPress has a large number of users, it has become the target of attackers. It is reported that attacks against WordPress websites have become more and more frequent since February this year. Several network security companies specializing in WordPress security products, such as Wordence, WebARX and NinTechNet, have reported increasing attacks on WordPress sites.

In February, it was reported that all new attacks focused on exploiting vulnerabilities in WordPress plug-ins, rather than problems with WordPress itself. Many attacks target recently patched plug-in vulnerabilities. Hackers hope to hijack websites before webmasters have the opportunity to install security patches.

However, some attacks are also slightly more complex. Some attackers also found and began to exploit the zero day vulnerability. The following is a summary of the new WordPress plug-in vulnerability attacks that occurred in February. It is recommended that website administrators update the following WordPress plug-ins as soon as possible to avoid hacker attacks on related websites.

Duplicator

According to a report by Wordence, since mid February, hackers have exploited a vulnerability in Duplicator, a plug-in that allows site administrators to export their site content.

This vulnerability allows an attacker to export a copy of the site, extract database credentials from it, and then hijack the underlying MySQL server of the WordPress site 28 Repair.

To make matters worse, Duplicator is one of the most popular plug-ins on the WordPress portal. When the attack started on February 10, it was installed more than 1 million times. The commercial version of the plug-in, Duplicator Pro, installed on another 170000 sites, was also affected.

Profile Builder

There is another major vulnerability in the free and professional profile builder plug-ins, which allows hackers to register unauthorized management accounts on the WordPress website.

The vulnerability was fixed on February 10, but the attack started on February 24. According to the report, at least two hacker organizations are taking advantage of this vulnerability. More than 65000 sites (50000 using free versions, 15000 using commercial versions) are vulnerable unless they update the plug-in to the latest version.

ThemeGrill Demo Importer

Another vulnerability lies in the ThemeGrill Demo Importer, which comes with the sales business WordPress Theme Themes sold by ThemeGrill, a web development company.

WebARX, a WordPress security company, said that the old version of ThemeGrill Demo Importer was vulnerable to remote attacks by unauthenticated attackers. The hacker can reset the content of the site to zero, effectively clearing the content activated by the ThemeGrill theme in all WordPress sites, and installing vulnerable plug-ins.

In addition, if the site's database contains a user named "admin", the attacker will be granted access to the user, who has full administrator privileges of the site. More than 200000 sites have installed this plug-in. It is recommended to update it to v1.6 as soon as possible Version 3.

ThemeREX Addons

The security personnel also found an attack against the ThemeREX plug-in, which is a WordPress plug-in with all the ThemeREX business themes pre installed. According to Wordence's report, the attack started on February 18, when hackers discovered the zero day vulnerability of the plug-in and began to use it to create rogue management accounts on vulnerable sites.

Although the attack continues, no patch has been provided. The webmaster is advised to delete the plug-in from their website as soon as possible.

Flexible Checkout Fields for WooCommerce

The attack also targeted websites running the Flexible Checkout Fields for WooCommerce plug-in, which was installed on more than 20000 WordPress based e-commerce websites.

Hackers use a (now patched) zero day vulnerability to inject XSS payloads, which can be triggered in the login administrator's dashboard. The XSS payload allows hackers to create administrative accounts on vulnerable websites.

This type of attack has been carried out since February 26 [1,2].

In addition, Async JavaScript, 10Web Map Builder for Google Maps, and Modern Events Calendar Lite plug-ins also have similar zero day vulnerabilities, which have been applied to 100000, 20000, and 40000 sites, respectively. (zdnet)

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/1206.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

Multi store system management - store management design, how to do multi store system design scheme

Store management is an important part of the e-commerce platform. The platform administrator manages store information, goods, orders, settlement methods and other contents through the store management function. The author of this paper analyzes the design of store management in multi merchant system management. Let's have a look. 1、 Introduction The store management is an important part of the e-commerce platform. The platform administrator manages the store through
seven hundred and twenty-two
one
1 year ago (2024-02-19)

Sitecore: What major functions does a high-quality and powerful content management system need to have?

An appropriate content management system (CMS) is an urgent task for enterprises to maintain competitiveness through digital upgrading and transformation. Now 90% of enterprise website building and development uses CMS, which can easily create excellent customer experience in all channels, help enterprises attract new customers, retain old customers and turn existing customers into loyal customers, expand market share and increase revenue
three hundred and seventy-eight
zero
1 year ago (2024-02-18)

The combination and application of content management system and marketing technology, and the combination and application of content management system and marketing technology

B2B content marketing hopes to deliver valuable content to customers at their own stage in a timely manner during their purchase journey. Such as brand and solution related content in the cognitive stage, industry cases in the consideration stage and user confidence building stage, in-depth service introduction in the purchase stage, etc. These contents include images, videos, web pages, white papers
three hundred and seventeen
zero
1 year ago (2024-02-18)

In the second quarter, 648 websites were interviewed by the national network information system according to law, 56 websites were suspended from updating, and the spirit of the national network information work conference was ppt

According to the data released by "Cybertrust China", in the second quarter, the national Cybertrust system continued to strengthen administrative law enforcement, standardize administrative law enforcement, and investigate and deal with all kinds of illegal cases according to law. Original title: In the second quarter, 648 websites were interviewed by the national online trust system in accordance with the law, 56 websites were suspended from updating, and the TechWeb news on July 30 was released according to "online trust China"
three hundred and eleven
zero
1 year ago (2024-02-17)

Introduction and recommendation of ten free cms website building systems, and ten free defective software

It is particularly important to choose a easy-to-use cms website building system for website management and maintenance. We will choose different website building systems according to different website types, but the load, security, ease of use, versatility and subsequent development of the program are all basic criteria for everyone to choose a website building system. According to the webmaster station ranking and aleax ranking, the top 1
three hundred and seventy-six
zero
1 year ago (2024-02-17)

What are the advantages of Shanghai cms website?, How to build a website for cms

Original title: What are the benefits of building a website by Shanghai cms? Before the advent of cms, we usually found a website production company to carry out customized development. It can also be said that in fact, these website production companies also have their own formed website construction system, but it is not available for users to download. What we are talking about now is a website construction system that can be downloaded to build websites
three hundred and twenty-two
one

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: