Hackers target vulnerable WordPress Elementor plugin after releasing a Proof-of-Concept.
Hackers are now actively searching for vulnerable versions of the Essential Addons for Elementor plugin on thousands of WordPress sites in mass internet scans, attempting to exploit a critical account password reset flaw that was revealed earlier this month.
The critical flaw, identified as CVE-2023-32243, affects Essential Addons for Elementor versions 5.4.0 to 5.7.1. It allows unauthenticated attackers to arbitrarily reset administrator account passwords and take control of websites.
The flaw that affected over a million websites was discovered by PatchStack on May 8, 2023, and was patched by the vendor on May 11, with the release of version 5.7.2 of the plugin.
See also: LayerZero: Launches crypto bug bounty program offering $15M

See also: Hacking group Lemon Group has pre-installed Guerilla malware on Android devices
Scale of exploitation
On May 14, 2023, the researchers published a proof-of-concept exploit on GitHub, making the tool widely available to attackers.
At the time, a BleepingComputer reader and website owner reported that his website had been hit by hackers who exploited the flaw to reset the administrator password. However, the scale of the exploitation was unknown.
A Wordfence report published yesterday sheds more light, with the company claiming to have observed millions of attempts to detect the presence of the plugin on websites and to have blocked at least 6,900 exploitation attempts.
The day after the flaw was disclosed, WordFence recorded 5 million detection scans looking for the plugin's "readme.txt" file, which contains information about the plugin's version and therefore determines whether a website is vulnerable.
Most of these requests came from just two IP addresses, '185.496.220.26' and '185.244.175.65.'
In terms of exploitation attempts, the IP address “78.128.60.112” had a significant volume, using the PoC exploit published on GitHub. Other high-ranking attack IPs counted between 100 and 500 attempts.
See also: ChatGPT apps were actually fleeceware – Delete them now!
It is recommended that website owners using the “Essential Addons for Elementor” plugin immediately install version 5.7.2 or later in order to apply the available security update.
Additionally, website administrators should use the breach indicators listed in the Wordfence report and add the offending IP addresses to a block list to stop these and future attacks.
Users of the free Wordfence security package will be covered by protection against CVE-2023-32243 on June 20, 2023, so they are also currently exposed.
Information source: bleepingcomputer.com
