Advertisement
Top

Tag: WordPress


Vulnerabilities

Critical Bug in WordPress Plugins Open Sites to Hacker Takeovers

December 16, 2019

Via: Threat Post

Security researchers are warning users of two WordPress plugins – made by Brainstorm Force – that they need to patch a “major” vulnerability that could allow hackers to gain administrative access to any website using the plugins. According to Brainstorm […]


Vulnerabilities

Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS

September 26, 2019

Via: Threat Post

An unpatched vulnerability in the Rich Reviews plugin for WordPress is putting an estimated 16,000 sites in danger of stored cross-site scripting (XSS) attacks. Sites running the plugin are vulnerable to unauthenticated plugin option updates, which can be used to […]


Vulnerabilities

WordPress 5.2.3 Patches Several XSS Vulnerabilities

September 5, 2019

Via: Security Week

WordPress developers on Thursday announced the availability of version 5.2.3, a maintenance and security release that includes 29 fixes and enhancements, along with several security patches. As far as security is concerned, WordPress 5.2.3 mostly patches cross-site scripting (XSS) vulnerabilities. […]


Network security

Attackers are exploiting vulnerable WP plugins to backdoor sites

September 3, 2019

Via: Help Net Security

A group of attackers that has been injecting WordPress-based sites with a script redirecting visitors to malicious and fraudulent pages has now also started backdooring the vulnerable installations, Wordfence’s Mikey Veenstra warns. The attacks The attackers are exploiting vulnerabilities in […]


Vulnerabilities

WordPress Plugins Exploited in Ongoing Attack, Researchers Warn

August 26, 2019

Via: Threat Post

Researchers are warning of an ongoing campaign exploiting vulnerabilities in a slew of WordPress plugins. The campaign is redirecting traffic from victims’ websites to a number of potentially harmful locations. Impacted by the campaign is a plugin called Simple 301 […]


Vulnerabilities

WordPress Plugin Flaws Exploited in Ongoing Malvertising Campaign

July 24, 2019

Via: Threat Post

A widespread and ongoing malicious advertising campaign is exploiting several recently-disclosed WordPress plugin vulnerabilities to redirect website visitors to booby-trapped landing pages. Researchers at Wordfence said that they recently discovered bad actors injecting code into websites with the vulnerable plugins […]


Threats & Malware, Vulnerabilities

Vulnerability in WordPress Live Chat Plugin allows to steal and hijack sessions

June 12, 2019

Via: Security Affairs

Experts at Alert Logic have discovered a vulnerability in the popular WordPress Live Chat plugin that could be exploited by an unauthorized remote attacker to steal chat logs or manipulate chat sessions. The critical vulnerability, tracked as CVE-2019-12498, is a […]


Vulnerabilities

Exploits for Social Warfare WordPress Plugin Reach Critical Mass

April 24, 2019

Via: Threat Post

Active exploits for a recently disclosed bug in a popular WordPress plugin, Social Warfare, are snowballing in the wild – potentially putting more than 40,000 websites at risk. The vulnerability, CVE-2019-9978, tracks both a stored cross-site scripting (XSS) vulnerability and […]


Vulnerabilities

WordPress Yellow Pencil Plugin Flaws Actively Exploited

April 12, 2019

Via: Threat Post

The maker of a WordPress plugin, Yellow Pencil Visual Theme Customizer, is asking all users to immediately update after it was discovered to have software vulnerabilities that are being actively exploited. The attacker exploiting these flaws has been behind several […]


Hacker

Crooks use hidden directories of compromised HTTPS sites to deliver malware

April 3, 2019

Via: Security Affairs

Crooks are utilizing hidden “well-known” directories of HTTPS sites running WordPress and Joomla websites to store and serve malicious payloads. Hacked websites were used for several malicious purposes, experts observed compromised WordPress and Joomla websites serving Shade/Troldesh ransomware, coin miners, […]


Hacker, Network security

CSRF flaw in WordPress potentially allowed the hack of websites

March 14, 2019

Via: Security Affairs

Security researcher Simon Scannell from RIPS Technologies has discovered a new CSRF vulnerability in WordPress, that could potentially lead to remote code execution attacks. The flaw is a cross-site request forgery (CSRF) that resides in the comment section of WordPress […]


Vulnerabilities

WordPress Patches Privilege Escalation Vulnerabilities

December 18, 2018

Via: Security Week

Privilege escalation vulnerabilities in WordPress allow attackers to access features that were intended for administrators only, RIPS Tech security researchers say. An attacker with a user role as low as contributor on WordPress – the free and open-source content management […]


Vulnerabilities

Attackers Exploit Recently Patched Popular WordPress Plugin

November 23, 2018

Via: Security Week

Recently patched vulnerabilities in the popular AMP for WP plugin are being targeted in an active Cross-Site Scripting (XSS) campaign, Wordfence reports. With over 100,000 installs, the plugin adds Accelerated Mobile Pages (Google AMP Project) functionality to websites, which makes […]


Malware, Vulnerabilities

Critical WordPress Flaw Grants Admin Access to Any Registered Site User

November 19, 2018

Via: Threat Post

The privilege-escalation vulnerability would allow an attacker to inject malware, place ads and load custom code on an impacted website. Another day, another critical WordPress plugin vulnerability. The popular AMP for WP plugin, which helps WordPress sites load faster on […]


Cyber-crime, Security

Spambot aims at targets WordPress sites in World Cup-Themed spam scam

July 13, 2018

Via: Security Affairs

Security experts from Imperva recently observed a spike in spam activity directed at WordPress websites, attackers aimed at tricking victims into clicking on links to sites offering betting services on the 2018 FIFA World Cup games. Imperva monitored the activity […]


Vulnerabilities

Unpatched WordPress file deletion vulnerability could allow site takeover and code execution

June 28, 2018

Via: Security Affairs

Seven months ago, security experts discovered a critical file deletion vulnerability that affects all WordPress versions, currently, the issue is still unpatched. The vulnerability could be exploited to complete takeover of the websites running the popular CMS and gain arbitrary […]


Virus & Malware, Vulnerabilities

Take These Steps to Secure Your WordPress Website Before It’s Too Late

April 23, 2018

Via: Security Affairs

You might have heard that WordPress security is often referred to as “hardening.” While the name might cause a few eyebrows to raise, overall, it makes sense. To clarify, the process of adding security layers is similar to boosting the […]


Malware

WordPress Users Warned of Malware Masquerading as ionCube Files

February 28, 2018

Via: Threat Post

Security researchers are warning WordPress and Joomla admins of a sneaky new malware strain masquerading as legitimate ionCube files. The malware, dubbed ionCube Malware, is used by cybercriminals to create backdoors on vulnerable websites allowing them to steal data or […]


Vulnerabilities

WordPress Sites Exposed to Attacks by ‘Formidable Forms’ Flaws

November 16, 2017

Via: Security Week

Vulnerabilities found by a researcher in a popular WordPress plugin can be exploited by malicious actors to gain access to sensitive data and take control of affected websites. Formidable Forms, available both for free and as a paid version that […]


Cloud security, Vulnerabilities

WordPress Delivers Second Patch For SQL Injection Bug

November 2, 2017

Via: Threat Post

A bug exploitable in WordPress 4.8.2 and earlier creates unexpected and unsafe conditions ripe for a SQL injection attack, exposing sites created on the content management system to takeover. WordPress released WordPress 4.8.3 Tuesday, which mitigates the vulnerability. “This is […]