Users who use WordPress to manage their websites are likely to find the recently exposed security vulnerability in one of the plug-ins. A security researcher from WebARX has just discovered a flaw in the "Simple Social Buttons" plug-in. This plug-in is designed to facilitate webmasters to embed social sharing buttons on SNS platforms such as Facebook or Twitter in articles, comments, or other parts of the website.
However, the newly exposed vulnerability allows any user who can create a new account on the website to use it to access "settings that can usually only be removed by the administrator". In other words, an attacker with ulterior motives can take over the website through this plug-in.
Security researchers pointed out that up to now, the WPBrigade simple social sharing button plug-in has been downloaded more than 500000 times. WordPress claims that it has been adopted by more than 40000 websites.
Simple Social Buttons Exploit PoC by WebARX( via )
This means that many websites built on the platform may have been affected by the vulnerability. Fortunately, security researchers reported this problem to WordPress last week, and the official released an update the next day.
Of course, in order to ensure security, please be sure to upgrade the plug-in to the latest version 2.0.22.
[Compiled from: Neowin]
[Source: cnBeta. COM]