HomeSecurityHacked WordPress core file used to control traffic!

Hacked WordPress core file used to control traffic!

With WordPress dominating the CMS market by far, hackers are becoming more creative and aggressive in taking over websites and spreading infections as widely as possible.

A new trick discovered by Sucuri over the past few weeks has seen hackers exploit yet another WordPress core file to inject malicious code into compromised websites and redirect traffic to malicious websites.

The file in question is wp-includes/template-loader.php, a core WordPress file that is responsible for managing the site's themes page.

Hacked WordPress core file used to control traffic!

In this most recent incident, hackers had altered this file to simply redirect someone from the legitimate website traffic to a malicious page offering users product keys for various Microsoft products at discounted prices.

For years, hackers have been hacking websites, and in most cases, uploading their own custom files to each hacked server. That's why webmasters and developers have created security solutions that check if new files have been added recently and notify users.

As these products became more popular and slowly evolved into more comprehensive Web Application Firewalls (WAFs), hackers also had to adapt and began nesting their malicious code within plugins, themes, or core CMS files.

While users often removed plugins and themes from their websites, attackers slowly began to prefer the core CMS files to host their malicious code. Incidents where WordPress files were hacked and had their core CMS files replaced have been reported in the past.

In most cases, these hacks were used to spread SEO spam, but this latest incident shows that they can be used for anything a hacker desires.

While in this case, the traffic was sent to a “fake” website offering questionable “product keys,” the attacker could have very easily redirected the malicious traffic to an exploit kit and attempted to infect the user with malware.

In today's current state of the Internet, if you run a site with relatively good search engine rankings, it is recommended that you start looking for a WAF professional or at least a script that offers file integrity monitoring and corresponding notification.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS