HomeSecurity730,000 WordPress sites updated - critical plugin bug fixed

730,000 WordPress sites updated – critical plugin bug fixed

WordPress sites using Ninja Forms, a form-building plugin with more than 1 million installations, were massively updated this week to a new version that addresses a critical security vulnerability that is likely being exploited by hackers.

See also: WordPress: Millions of attacks target Tatsu Builder plugin

WordPress

On June 16, 2022, the Wordfence Threat Intelligence team observed a back-ported security update in Ninja Forms, a WordPress plugin with over a million active installations. The team analyzed the plugin to determine the exploitability and severity of the vulnerability that had been patched.

The vulnerability is a code injection issue that affects many versions of Ninja, starting with version 3.0 and later.

Wordfence threat analyst Ramuel Gall discovered while reverse-engineering the patch that unauthenticated attackers can exploit this bug remotely to call various Ninja Form categories using a flaw in the Merge Tags feature.

See also: Elementor WordPress plugin: Critical vulnerability affects thousands of sites

Successful exploitation allows them to fully take over unpatched WordPress sites via several exploit chains, one of which allows remote code execution via deserialization to fully take over the targeted site.

Forced update and possible exploitation by hackers

Although there has been no official announcement, most vulnerable websites appear to have been forced to update based on the number of downloads since this flaw was patched on June 14.

According to Ninja Forms' download statistics, the security update has been rolled out more than 730,000 times since the patch was released.

If the plugin has not yet automatically updated to the latest version, you can manually apply the security update from the dashboard (the latest version protected from attacks is 3.6.11).

Wordfence analysts also found evidence indicating that this security flaw is already being used in ongoing attacks.

730,000 WordPress sites updated - critical plugin bug fixed

Forced updates used to fix critical bugs

This fits with previous cases when Automattic, the company behind the WordPress content management system, made forced updates to fix critical security flaws used by hundreds of thousands or millions of websites.

Samuel Wood, a WordPress developer, said in October 2020 that Automattic had used forced security updates to push “security releases for plugins multiple times” since the release of WordPress 3.7.

See also: WordPress: Critical vulnerabilities in Jupiter Themes and JupiterX Core plugin

As Automattic security researcher Marc Montpas told BleepingComputer in February, forced patching is used regardless of their administrators ' settings in "very rare and extremely serious cases."

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS