HomeSecurityWordPress: Massive attack on 900,000 websites

WordPress: Massive attack on 900,000 websites

WordPress is in the target of hackers, with a new massive attack against more than 900,000 websites.

The attacks appear to be the work of a hacker, who in the last month used at least 24,000 IP addresses to send malware to over 900,000 websites.

WordPress: Massive attack on 900,000 websites

After April 28, hacking attempts became more intense, while WordPress security company Defiant, which built the Wordfence security plugin, detected, on May 3, over 20 million attacks on more than 500,000 websites.

Defiant QA manager Ram Gall said the hacker has focused more on exploiting cross-site scripting (XSS) vulnerabilities in plugins that have been patched in the past and have been targeted in other attacks.

Redirecting visitors to malicious ads is a successful hacking. If the user is logged in to the browser that is running the JavaScript, the code tries to insert a PHP backdoor into the header file, along with another JavaScript. The backdoor takes another payload and stores it in the header, attempting to execute it. In this way, the hacker can change the payload into a webshell, code that creates a malicious administrator or deletes the content of an entire site. In its announcement, Defiant included exposure indicators in the final payload.

WordPress: Massive attack on 900,000 websites

Here is the list of vulnerabilities that appear to be most targeted and the Plugins have either been removed or patched previously, according to Gall.

  1. An XSS vulnerability, in the Easy2Map plugin, which was removed from WordPress in August 2019, is estimated to have been installed on fewer than 3,000 websites.
  2. A vulnerability in WP GDPR Compliance's update options, which allowed attackers, among other things, to change the URL of sites, was fixed in late 2018. Despite the fact that this plugin exceeded 100,000 installs, it is estimated that no more than 5,000 websites have been affected.
  3. An XSS vulnerability, in Blog Designer, which was patched in 2019. It is estimated that fewer than 1,000 vulnerable installations remain, although this vulnerability was a target of previous hacking campaigns.
  4. A vulnerability in the options update in Total Donations allows hackers to change the website's homepage URL. This plugin was permanently removed from the Envato Marketplace in early 2019 and is estimated to have fewer than 1,000 total installations remaining.
  5. An XSS vulnerability in the Newspaper theme that was fixed in 2016. This vulnerability has also been targeted in the past.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS