WordPress plugin is vulnerable. The website may be taken over by an attacker, and wordpress is attacked

One year ago (2023-11-30) Chief Editor
2 minutes
two hundred and forty-nine
zero

IT Home reported on February 14 that WebARX, a foreign security agency, recently issued a warning because of the old version of WordPress Simple

On February 14, IT Home reported that WebARX, a foreign security agency, recently issued a warning that because the old version of WordPress Simple Social Button plug-in had a vulnerability, the website using the plug-in might be taken over by an attacker. They suggested that these websites be upgraded to the latest version as soon as possible.

It is understood that the Simple Social Button plug-in, developed by WPBrigade, is a very popular WordPress plug-in. This plug-in allows administrators to add community sharing buttons on the WordPress website, and can also directly provide web messages and community account login.

According to the statistics of WordPress Plugin, the plug-in has been installed by more than 40000 users, while the number of downloads on the official website of WPBrigade has exceeded 570000. Due to the improper design process of the plug-in application and the lack of license testing, this plug-in has a privilege upgrade vulnerability in the old version. An attacker can use this vulnerability to elevate the permissions of a new account on WordPress. An attacker can even modify the WordPress plug-in to reveal the vulnerability, and the website may be taken over by the attacker.

If the WordPress administrator has forbidden users to register accounts or is free from vulnerability hazards, but if the website allows you to leave messages for blog posts, you may be attacked. The vulnerability was reported to WPBrigate on February 7, and WPBrigate then completed the repair on the next day. This vulnerability affects Simple Social Button versions before 2.0.4 and 2.0.22. The website administrator needs to update as soon as possible.

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/1210.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

What are the main contents of wms system in warehouse management

Original title: What does the wms system mainly embody in warehouse management? What does the wms system mainly embody in warehouse management? Warehouse management has standardized and intelligent process oriented management. A good warehouse management mechanism can improve the efficiency of warehouse managers, relieve their pressure, and complete efficient and accurate work. 1. Warehouse management is accompanied by the progress of the times
1 year ago (2024-02-18)

How to implement the mptt comment function of CMS content management system in Django?, Django management page

During the daily development of content related Web systems in the directory, whether it is Blog or CMS, if you need to add links to interact with users, you must need the comment function. Next, you can implement the comment reply function in Django based on Python's MPTT framework. Note: Because the user comment function will involve a
three hundred and ninety-four
zero
1 year ago (2024-02-18)

Best CMS content management system in 2022, good novel in 2021

Looking for the best CMS software to build your website? At a high level, CMS or content management systems can help you create functional websites without having to use code to build every page from scratch. However, different CMS software has different advantages and disadvantages, so you need to choose the tool that best suits your specific needs and budget. To help, we accept
four hundred and six
zero
1 year ago (2024-02-18)

Shenzhen promotes the access of 5G base station energy storage system to the virtual power plant management center in the city. Does the Shenzhen 5g government subsidize the flow package charge

Xinhua News Agency, Shenzhen, December 14 (Reporter Wang Feng) At the 2022 Carbon Peak Carbon Neutralization Forum and Shenzhen International Low Carbon City Forum held here in Shenzhen, Shenzhen Virtual Power Plant Management Center signed a cooperation agreement on virtual power plant construction with China Tower, China Telecom, China Mobile, China Unicom, Huawei Digital Energy and other units on the 13th, which will jointly promote the city's 5G base station energy storage system
three hundred and forty-three
zero
1 year ago (2024-02-18)

Common website cms content management system recommendation, common website cms content management software

CMS is the abbreviation of "Content Management System", which means "Content Management System" in Chinese. These systems have developed common website functions and provided them to users for download, greatly improving the efficiency of website construction. The most common functions of CMS are column management, article management, product management, picture management
three hundred and twenty-eight
zero

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: