HomeSecurityGoogle WordPress plugin: Update immediately if you don't want them to "drop" your site...

Google WordPress plugin: Update immediately if you don't want your site to be "thrown down"!

Google WordPress plugin: A critical bug was found in Google's official WordPress Plugin, with 300,000 active installations, which could allow hackers to gain owner access to targeted Google Search Console sites .

Site Kit is a WordPress plugin designed by Google to provide website owners with details about how visitors found or use their website. It pulls the information through official statistics collected from various Google tools and displays it directly in the WordPress dashboard.

Google WordPress plugin: Update immediately if you don't want your site to be "thrown down"!

It also makes it easy to set up and configure key Google tools such as Search Console, Analytics, Tag Manager, PageSpeed ​​Insights, Optimize, and AdSense.

Google Search Console Privilege Escalation

The Google Search Console privilege escalation vulnerability was discovered by the Wordfence Threat Intelligence team on April 21 and reported to Google the following day.

The bug was caused by the disclosure of proxySetupURL in the HTML of the admin pages. The URL is used to connect Site Kit to Google Search Console via Google OAuth.

Google WordPress plugin: Update immediately if you don't want your site to be "thrown down"!

The vulnerability was linked to another issue: the verification request, used to confirm ownership of a website, was a registered administrator action - it did not allow requests from an authenticated WordPress user. ’s ranking and reputation website”according to Wordfence.

The ways in which they can be used to the benefit of hackers vary, with the following being on the list:

  • Facilitating Black Hat Seo campaigns through search engine result pages
  • Introduction of malicious code for illegal monetization
  • Removing pages from Google search engine results pages (SERPs)
  • Modify sitemaps
  • View competitive performance data

Google has anticipated this problem, and will notify website owners with automatic messages whenever a new owner is added to the website, while "A website's rights holders can change settings that affect how Google search interacts with the website or app."

In case the notification message has been saved in spam emails, Wordfence provides instructions on how to confirm the integrity of Google Search Console ownership, and check if a malicious administrator has been added and remove it.

This vulnerability was fixed on May 7, with the release of Site Kit 1.8.0, after the security flaw was published to the Github Repository on May 4. It is recommended that all users install the latest version, which is fully up-to-date.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS