A critical vulnerability in the WP Automatic WordPress plugin backdoors is being exploited by hackers to create user accounts with administrative privileges and deploy that offer long-term access.

The WP Automatic plugin is installed on over 30,000 WordPress sites and allows administrators to automate the insertion of content (e.g. text, images, videos) from various online sources.
The vulnerability used by hackers is tracked as CVE-2024-27956 and is considered critical (9.9/10).
See also: Forminator plugin: Critical vulnerability affects thousands of WordPress sites
It was discovered by researchers at PatchStack on March 13 and was described as an SQL injection issue affecting WP Automatic versions prior to 3.9.2.0. The issue is located in the user authentication mechanism. Using the vulnerability, hackers can bypass the authentication by submitting SQL queries to the website's database . Attackers can use specially crafted queries to create administrator accounts on the targeted website.
Over 5.5 million attack attempts
Since the security issue was disclosed, Automattic's WPScan has observed more than 5.5 million attempts to exploit the vulnerability, with the majority recorded on March 31.
WPScan reports that after gaining admin access to the target website, hackers create backdoors.
To prevent a new breach by other hackers (via the same vulnerability) and to avoid detection, the hackers rename the vulnerable file to “csv.php”.
See also: Crypto drainers exist on thousands of WordPress sites
Once they gain control of the WordPress site, attackers can install other plugins that allow file uploads and code editing.
WPScan provides a set of breachthat can help administrators determine if their website has been compromised.
Administrators can check for a potential breach by looking for the presence of an administrator account starting with “xtw” and files named web.php and index.php, which are the backdoors.
To mitigate the risk of a breach, researchers recommend updating the WP Automatic WordPress plugin to version 3.92.1 or later.

WPScan also recommends that website owners frequently back up their website.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
See also: WP-Members Membership: Vulnerability puts WordPress sites at risk
Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with your customers. If data is compromised, they are likely to take legal action against you and switch to other companies.
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers’ trust, preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
