HomeSecurityCritical vulnerabilities in WordPress plugin: Update immediately!

Critical vulnerabilities in WordPress plugins: Update immediately!

WordPress

Two very serious vulnerabilities have been found in the WordPress PageLayer plugin, which if exploited by hackers could allow the deletion of content on vulnerable WordPress sites or even gaining complete control over them.

PageLayer is a WordPress plugin with over 200,000 active installations . It can help users without programming or design skills create websites using a browser-based drag-and-drop real- time editor .

The vulnerabilities were reported to the PageLayer developer by the Wordfence Threat Intelligence in late April. The developer released an updated version of the plugin (1.1.2) on May 6, which, among other things, fixed these bugs.

According to Wordfence, the two vulnerabilities can be used by cybercriminals to delete the content of WordPress sitesrunning older versions of the plugin, as well as for takeover attacks.

One vulnerability allows attackers to update and modify posts with malicious content, as well as many other things.

The second flaw allows attackers to make a request, on behalf of the site administrator, that can 's settings plugin. This could allow malicious Javascript injection.

vulnerabilities

As further analyzed by the researchers, the bugs make it possible for attackers to insert malicious JavaScript code, alter sites, create fake administrator accounts, redirect visitors to malicious sites, and “exploit a site user’s browser to compromise their computer .”

More details about the two vulnerabilities in the WordPress PageLayer plugin, their impacts, and how they were fixed can be found in the Wordfence report

To avoid potential attacks, users should immediately update PageLayer to version 1.1.2.

At least 120,000 sites are still vulnerable

PageLayer 1.1.2 was released on May 6th, and as of yesterday it had about 85,000 new downloads (new installations and simple updates).

This means that around 120,000 WordPress sites are still vulnerable to ifattack hackers exploit the vulnerabilities.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS