HomeSecurityWordPress: Hackers target 1.5 million websites

WordPress: Hackers target 1.5 million websites

Ongoing attacks are targeting a vulnerability in the Beautiful Cookie Consent Banner plugin in WordPress, which lacks sufficient authentication and can cause Unauthenticated Stored Cross-Site Scripting (XSS) . This plugin is installed on more than 40,000 websites .

See also: Hackers target vulnerable WordPress Elementor plugin after Proof-of-Concept release

WordPress

In XSS attacks, attackers inject malicious JavaScript into vulnerable web pages, which will be executed in visitors' browsers.

The impact can result in unauthorized access to sensitive information, session hijacking, malware via redirects to malicious websites, or a complete compromise of the target's system.

WordPress security firm Defiantdiscovered the attacks and says the vulnerability allows unverified attackers to create administrator accounts on WordPress sites running outdated plugin versions (as low as version 2.10.1).

The security issue exploited by this campaign was addressed in January with version 2.10.2.

"According to our records, the vulnerability has been actively attacked since February 5, 2023, but this is the largest attack against it to date," said threat analyst Ram Gall.

«We have blocked nearly 3 million attacks on more than 1.5 million websites, from almost 14,000 IP addresses since May 23, 2023, and the attacks continue».

See also: WordPress plugin flaw exploited after PoC exploit

additive

Although the attack is large‑scale, Gall says that the threat actor is using an incorrect exploitation method that may not cause any harm if the target is a WordPress site with a vulnerable plugin version.

However, administrators or website owners using the Beautiful Cookie Consent Banner plugin are advised to update it to the latest version, because even a failed attack could corrupt the plugin configuration stored in the nsc_bar_bannersettings_json.

New versions of the plugin have been upgraded and include fixes to protect against website attacks.

Even though the attacks do not inject malicious payloads into the websites, the threat actor behind them can strike at any time and infect any exposed websites.

Last week, authorities scoured the Internet for WordPress sites using vulnerable versions of the Essential Addons for Elementor and WordPress Advanced Custom Fields.

See also: Critical vulnerability in WordPress plugin “Essential Addons for Elementor”

The attacks began after a leaked source code was published online ,allowing unauthorized users to compromise websites. This happens when they change administrator passwords and gain access to sensitive data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS