Search This Blog
Popular Posts
-
Elegant Themes has been developing WordPress themes for a long time. It has developed lots of popular themes including Divi, Nexus, Fa...
-
This is part of our "Learn WordPress" series. In this post, you will find out how to properly set up WordPress after creati...
-
It has not only changed the traditional perspective of buyers and sellers, but also revolutionized the entire concept of retail busine...
-
Hello there! My blog post 'Spikes' was published on Sept. 22nd; however, the post before it called 'Flow' was published on...
-
LIST MAG WP is a beautifully designed WordPress Theme that is built to be engaging, fast and most importantly boost viral traffic with...
-
Lifegate is a modern looking and elegant WordPress Blog Theme with plenty of straightforward and complete functionalities to build up a pe...
-
What comes to mind when you hear of WordPress? For a majority of people, blogging comes to mind. To other people who are professionals in we...
-
WordPress has rolled out a new version dubbed 4.2.3 of its content management system (CMS) to patch a critical cross-site scripting (XSS) vu...
-
Fashionate is a great looking free fashion blog theme for WordPress by ThemeExpert, it features a well structured and clean layout, an ima...
-
June 21, 2016 — Earndaddy.com, an informative and educational blog site for topics related to online marketing and earning money online,...
Blog Archive
- December (18)
- November (29)
- October (27)
- September (29)
- August (31)
- July (30)
- June (29)
- May (29)
- April (30)
- March (31)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (30)
- August (43)
- July (42)
- June (33)
- May (43)
- April (36)
- March (37)
- February (31)
- January (4)
- December (1)
- November (1)
- October (24)
- September (24)
- August (25)
- July (28)
- June (18)
- September (1)
Total Pageviews
Blogroll
Over 10,000 WordPress sites vulnerable to exploit
Security researchers have warned that over 10,000 websites powered by the WordPress content management system (CMS) are at risk of exploit due to a plugin containing a zero-day flaw.
The WP Mobile Detector plugin is the source of the issue, containing a zero-day vulnerability first disclosed by the Plugin Vulnerabilities team.
The security researchers became aware of a potential problem after receiving a HEAD request for a WP Mobile Detector file, blog/wp-content/plugins/wp-mobile-detector/resize.php, on a CMS domain which did not have the software installed.
The team investigated further and realized it was most likely that "someone was checking for the existence of the file before trying to exploit a vulnerability in the plugin."
The vulnerability itself is "easy to exploit," according to Sucuri. The zero-day can compromise a website and act as a backdoor to the CMS simply through sending the HEAD request with the backdoor URL.
"It's a simple vulnerability that stems from failing to validate and sanitize input from untrusted sources," Sucuri says. "No security checks are performed and an attacker can feed the src variable with a malicious URL that contains a PHP code."
Cyberattackers leveraging the flaw have been using the problem to load websites with porn and spam-related scripts.
The team behind WP Mobile Detector were informed of the zero-day vulnerability on 29 May and the wordpress.org Plugin Directory was notified two days later, leading to the temporary removal of the plugin.
Several days ago, there were over 10,000 active installations of the plugin recorded.
On 31 May, the developers of the plugin patched the issue and the plugin has been restored. Users should update to either version 3.6 or 3.7, both of which are now no longer vulnerable to attacks exploiting the vulnerability.
Read on: Top picks
Source: Over 10,000 WordPress sites vulnerable to exploit
0 comments:
Post a Comment