Site icon TheCyberThrone

WordPress Attack

Advertisements

Hackers are attempting to take over tens of thousands of WordPress sites by exploiting critical vulnerabilities including a zero-day in multiple plugins that allow them to create rogue administrator​​​ accounts and to plant backdoors.

The attacks on WordPress sites have started yesterday by targeting a zero-day unauthenticated stored XSS bug found in the Flexible Checkout Fields for WooCommerce plugin with 20,000 active installations by researchers at NinTechNet.

While the plugin’s development team WP Desk pushed out version 2.3.2 to fix the actively targeted security flaw within an hour after receiving the disclosure report from NinTechNet, some users were hacked until it was available and ready to install.

Three critical bugs has been found

a subscriber+ stored XSS in Async JavaScript (100,000+ installs)

an unauthenticated+ stored XSS in 10Web Map Builder for Google Maps (20,000+ installs)

and multiple subscriber+ stored XSS in Modern Events Calendar Lite (40,000+ installs)

Indicators of compromise

Exit mobile version