Best Website-BuildersBest Website-Builders
    What's Hot

    Ukraine war: Latvia sends cars seized from drunk drivers to help Kyiv

    March 9, 2023

    WhatsApp would take block over UK bill encryption plans

    March 9, 2023

    SVB Stock Price Crashes 38% After Bond Firesale Spurs Losses

    March 9, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website-BuildersBest Website-Builders
    • Home
    • CSS

      National Assembly amends standing order to allow CS to attend House of Commons from 23 March » Capital News

      March 9, 2023

      Apple Releases Safari Technology Preview 165 – Brings Bug Fixes and Performance Improvements

      March 9, 2023

      15 Best Courses to Become Full Stack Developer in 2023

      March 9, 2023

      Junior DevOps Engineer at Datafin Recruitment

      March 9, 2023

      Cricket betting tips and fantasy cricket match predictions: Sharjah Hundred League 2023

      March 9, 2023
    • Joomla

      Web Content Management Systems Market Business Growth Potential 2023-2030

      March 6, 2023

      How to create a successful content strategy framework

      March 3, 2023

      Free Website Hosting Services for Efficient and Reliable Work

      March 2, 2023

      Bluehost Review 2023 – Is It the Fastest Hosting Service?

      March 2, 2023

      Intermediate PHP Developer – Gauteng Johannesburg

      March 1, 2023
    • PHP

      Seth Rogen got brutally honest about not having kids

      March 9, 2023

      Jennifer Lawrence is reinventing herself for a comeback

      March 9, 2023

      March 9, 2023 — Biggest news story of the day

      March 9, 2023

      Likely to get worse, according to asthma experts

      March 8, 2023

      ‘Who Killed Robert Wone?’ by Peacock

      March 8, 2023
    • UX

      Top Design Agencies in March, According to DesignRush

      March 9, 2023

      Spotify announces new tools and features to improve user experience

      March 9, 2023

      Think Silicon to Showcase Latest Ultra-Low-Power Graphics and AI Solutions for Edge Computing at Embedded World 2023

      March 9, 2023

      Think Silicon to Showcase Latest Ultra-Low-Power Graphics and AI Solutions for Edge Computing at Embedded World 2023

      March 9, 2023

      PS5 System Update 7.0 Rolling Out Worldwide

      March 9, 2023
    • Web Builders
      1. Web Design
      2. View All

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      Can Religious Freedom Be Saved? This group is racing the clock to teach America’s first freedom

      February 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023

      Is There A Market For Rap-Themed Slot Games? – Rap Review

      January 19, 2023
    • WordPress

      Creed 3 is coming to Prime Video soon, but it won’t be available to stream for free

      March 9, 2023

      Bing now has 100 million users powered by ChatGPT, but will it continue?

      March 9, 2023

      This is the gaming laptop deal you need to buy now if you care about portability.

      March 9, 2023

      Microsoft 365 is launching Accessibility Assistant

      March 9, 2023

      Microsoft slowly but surely admits that Windows 11’s taskbar was wrong.

      March 9, 2023
    • Realtoz
      • Our Other Sites
    • More News
    Best Website-BuildersBest Website-Builders
    Home » A buggy WordPress plugin can completely take over your site • The Register
    Wordpress

    A buggy WordPress plugin can completely take over your site • The Register

    websitebuildersnowBy websitebuildersnowJuly 15, 2022No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Malicious actors have reportedly scanned approximately 1.6 million websites in an attempt to exploit a previously disclosed buggy WordPress plugin arbitrary file upload vulnerability.

    The vulnerability, tracked as CVE-2021-24284, targets the Kaswara Modern WPBakery Page Builder Addons and, when exploited, allows criminals to upload malicious JavaScript files and completely take over the organization’s website. even possible.

    Wordfence disclosed the vulnerability nearly three months ago and warned in a new advisory this week that criminal attacks are on the rise — the WordPress security shop hits customer sites an average of 443,868 times per day. claims to have blocked an attack attempt by

    The software developer never patched the bug and the plugin is currently closed. This means that all versions are susceptible to attack. Bug hunters estimate that between 4,000 and 8,000 websites still have the vulnerable plugin installed, and 1,599,852 unique sites were targeted, the majority of which were running the plugin. did not.

    However, if you’re still in the camp of running buggy plugins, now is a good time to unplug.

    Additionally, even if not directly affected, any of these vulnerable websites could be compromised and defaced to engage in other attacks such as phishing or hosting malware. , showing that even minor plugins can facilitate broader cybercrime on the Internet.

    “We strongly recommend that you remove Kaswara Modern WPBakery Page Builder Addons completely as soon as possible and find alternatives as your plugin is unlikely to receive a patch for this critical vulnerability,” warns Wordfence. did.

    According to security vendors, most attacks start with a POST request sent to /wp-admin/admin-ajax.php using the plugin’s uploadFontIcon AJAX action, allowing the malicious party to access the victim’s website. Malicious files can be uploaded. Wordfence explained:

    The logs may show the following query string for these events:

    Our threat intelligence team also noted that most of the exploit attempts came from these 10 IPs.

    • Blocked 1,591,765 exploit attempts on 217.160.48.108
    • 5.9.9.29 blocked 898,248 exploit attempts
    • 2.58.149.35 blocked 390,815 exploit attempts
    • 276,006 exploit attempts blocked on 20.94.76.10
    • 212,766 exploit attempts blocked on 20.206.76.37
    • 187,470 exploit attempts blocked on 20.219.35.125
    • 102,658 exploit attempts blocked on 20.223.152.221
    • 5.39.15.163 blocked 62,376 exploit attempts
    • Blocked 32,890 exploit attempts on 194.87.84.195
    • 31,329 exploit attempts blocked on 194.87.84.193

    Most attacks also include an attempt to upload a zip file named a57bze8931.zip. Once this file is installed, the criminal can continue to upload software to the victim’s girlfriend’s website.

    Additionally, according to Wordfence, some of the attacks also contain indications of the NDSW Trojan horse. This redirects site visitors to a malicious website. This is another reminder that it’s time to remove the patch now. ®



    Source link

    Share this:

    • Tweet
    • Email
    • Pocket
    • Mastodon
    • WhatsApp
    • Telegram
    • Share on Tumblr
    • Print
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleSEO: WordPress plugin to display old posts
    Next Article 5 Easiest Online Website Builders to Design Your Site Without Coding
    websitebuildersnow
    • Website

    Related Posts

    Creed 3 is coming to Prime Video soon, but it won’t be available to stream for free

    March 9, 2023

    Bing now has 100 million users powered by ChatGPT, but will it continue?

    March 9, 2023

    This is the gaming laptop deal you need to buy now if you care about portability.

    March 9, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Ukraine war: Latvia sends cars seized from drunk drivers to help Kyiv

    March 9, 2023

    WhatsApp would take block over UK bill encryption plans

    March 9, 2023

    SVB Stock Price Crashes 38% After Bond Firesale Spurs Losses

    March 9, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.