HomeSecurityWordPress: Which plugin versions have been recently attacked?

WordPress: Which plugin versions have been recently attacked?

WordPress : Which plugin versions have been recently attacked?

A new flaw in the popular WordPress has led to the exploitation of numerous sites using the platform. Specifically, it is a flaw found in the GDPR Compliance plugin.

Which versions are most susceptible to attacks?

WordPress versions of the “WP GDPR Compliance” plugin prior to 1.4.3 are more vulnerable and more easily attacked. The attack does not require any authorization and according to Sucuri.net, the attackers have already exploited a large number of sites. The sites that were attacked have changed URLs to “hxxp://realitatea[.]net”. This was confirmed by a careful Google search conducted the day before yesterday. The search showed that indeed around 7,600 sites changed their URLs to “realitatea[.]net”. Apparently, the malicious site went down later but when administrators and users tried to access their WordPress sites, most of them failed to load.

WordPress

Error details

The affected plugin typically manages who gets access and deletes requests that are not GDPR compliant. However, all versions of this plugin prior to 1.4.3 cannot properly handle the “save_setting”. Therefore, an attacker can enter arbitrary commands, which are saved until the plugin reaches the “do_action”.

Based on these flaws, an attacker can gain access to the site and make immediate changes, using malicious plugins for additional attacks.

The actions required immediately:

In case you have been attacked, as administrators you must edit the site's "wp_options" database to restore the correct URL. The "option_name" contains the value of "siteurl". In addition, you must manage the domain in the "option_value" field. Once the URL is corrected, the site will function normally, but you must definitely check for any malicious changes or uploads to the site. After completing this step, you must immediately proceed to upgrade to the next version so that there is no further problem and your site goes down again.

WordPress: Which plugin versions have been recently attacked?

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS