HomeSecurityHackers exploit new vulnerabilities in WordPress plugins

Hackers exploit new vulnerabilities in WordPress plugins

Cybersecurity researchers have warned that cybercriminals are using serious vulnerabilities in WordPress pluginsto create fraudulent administrator accountsto further exploit sites.

WordPress plugin vulnerabilities

“These vulnerabilities are found in various WordPress plugins and allow stored cross-site scripting (XSS) attacks, due to insufficient input sanitization and output escaping, making it possible to insert malicious scripts,” said researchers Simran Khalsa, Xavier Stevens, and Matthew Mathur of Fastly.

See also: Slider Revolution: Two vulnerabilities found in WordPress plugin

The vulnerabilities used by attackers are:

CVE-2023-6961 (CVSS score: 7.2) – Unauthorized Stored Cross-Site Scripting in WP Meta SEO

CVE-2023-40000 (CVSS score: 8.3) – Unauthorized Stored Cross-Site Scripting in LiteSpeed ​​Cache ​​

CVE-2024-2194 (CVSS score: 7.2) – Unauthorized Stored Cross-Site Scripting in WP Statistics

Most attacks exploiting WordPress plugin vulnerabilities involve injecting a payload that leads to an obfuscated JavaScript file hosted on an external domain. This is responsible for creating a new administrator account, inserting a backdoor, and setting up monitoring scripts .

The backdoors are inserted into both plugin and theme files, while the tracking script is designed to send an HTTP GET request containing HTTP host information to a remote server (“ur.mystiqueapi[.]com/?ur”).

See also: Hackers exploit Deskky Snippets WordPress Plugin and steal credit card details

Researchers identified a significant percentage of exploitation attempts.

WordPress security firm WPScanhad previously uncovered similar attack attempts that used the CVE-2023-40000 vulnerability to create administrator accounts.

To mitigate the risks of such attacks, WordPress website owners are advised to check their installed plugins, apply the latest updates , and check websites for signs of malware or the presence of suspicious admin users.

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Hackers exploit new vulnerabilities in WordPress plugins
Hackers exploit new vulnerabilities in WordPress plugins

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

See also: UserPro plugin – WordPress: Warning! Critical vulnerability

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers  ’ trust , preserving your company’s reputation, and staying on top of the competition.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS