Search This Blog
Popular Posts
-
Elegant Themes has been developing WordPress themes for a long time. It has developed lots of popular themes including Divi, Nexus, Fa...
-
Flickr/Laura D'Alessandro See Also I took Harvard Business School's new pre-MBA course online — and it is definitely w...
-
Hello there! My blog post 'Spikes' was published on Sept. 22nd; however, the post before it called 'Flow' was published on...
-
Hi there! There isn't a true e-commerce solution here at WordPress.com. You can, however get a PayPal button. If you get a PayPal bu...
-
Good news for the secure web: WordPress will now encrypt the traffic for over a million more websites that are hosted on its servers. Wo...
-
I will publish an article only when I have something important to say. That's what I reminded myself every time the egocentric ...
-
How to start a blog or website in 5 minutes with WordPress. After publishing the post on how I started blogging full-time, I'v...
-
KOZHIKODE: E A Jabbar, a retired teacher and an activist of Malappuram based Yukthi vadi Sangham, has filed a complaint before chief minis...
-
At the ripe young age of 32, back in 2009, Uber CEO Travis Kalanick apparently launched a Wordpress blog called Swooshing, and for some ...
-
The WordPress project released today version 4.5.2 of the WordPress open-source platform that contains two security issues in two librarie...
Blog Archive
- December (18)
- November (29)
- October (27)
- September (29)
- August (31)
- July (30)
- June (29)
- May (29)
- April (30)
- March (31)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (30)
- August (43)
- July (42)
- June (33)
- May (43)
- April (36)
- March (37)
- February (31)
- January (4)
- December (1)
- November (1)
- October (24)
- September (24)
- August (25)
- July (28)
- June (18)
- September (1)
Total Pageviews
Blogroll
Over 10,000 WordPress sites vulnerable to exploit
Security researchers have warned that over 10,000 websites powered by the WordPress content management system (CMS) are at risk of exploit due to a plugin containing a zero-day flaw.
The WP Mobile Detector plugin is the source of the issue, containing a zero-day vulnerability first disclosed by the Plugin Vulnerabilities team.
The security researchers became aware of a potential problem after receiving a HEAD request for a WP Mobile Detector file, blog/wp-content/plugins/wp-mobile-detector/resize.php, on a CMS domain which did not have the software installed.
The team investigated further and realized it was most likely that "someone was checking for the existence of the file before trying to exploit a vulnerability in the plugin."
The vulnerability itself is "easy to exploit," according to Sucuri. The zero-day can compromise a website and act as a backdoor to the CMS simply through sending the HEAD request with the backdoor URL.
"It's a simple vulnerability that stems from failing to validate and sanitize input from untrusted sources," Sucuri says. "No security checks are performed and an attacker can feed the src variable with a malicious URL that contains a PHP code."
Cyberattackers leveraging the flaw have been using the problem to load websites with porn and spam-related scripts.
The team behind WP Mobile Detector were informed of the zero-day vulnerability on 29 May and the wordpress.org Plugin Directory was notified two days later, leading to the temporary removal of the plugin.
Several days ago, there were over 10,000 active installations of the plugin recorded.
On 31 May, the developers of the plugin patched the issue and the plugin has been restored. Users should update to either version 3.6 or 3.7, both of which are now no longer vulnerable to attacks exploiting the vulnerability.
Read on: Top picks
Source: Over 10,000 WordPress sites vulnerable to exploit
0 comments:
Post a Comment