HomeSecurityWordPress: The vulnerabilities most used by hackers in Q1 2025

WordPress: The vulnerabilities most exploited by hackers in Q1 2025

Cybercriminals are constantly looking for security holes to target and infect WordPress sites. Here we will look at the vulnerabilities of WordPress plugins / themes that hackers used the most during the first quarter of 2025to compromise websites.

WordPress hackers vulnerabilities 2025

These are four vulnerabilities that were discovered and patched in 2024, but some users have not applied the updates. As a result, attackers can still exploit them to execute malicious code or steal sensitive data. All four vulnerabilities are considered critical, according to Patchstack.

See also: WP Ghost WordPress: Critical vulnerability puts thousands of sites at risk

Let's look at them in detail:

  • CVE-2024-27956: A SQL injection vulnerability in the WordPress Automatic Plugin, which has over 40,000 installations. The vulnerability allows unauthorized attackers to execute code via the auth POST parameter in the CSV export feature. The vulnerability is said to have first been exploited by hackers in May 2024. Patchstack says its virtual patch has blocked more than 6,500 attacks so far this year. Users are advised to apply version 3.92.1 of the plugin or later to fix the vulnerability.
  • CVE-2024-4345: A vulnerability in the Startklar Elementor Addons plugin (5,000+ installations), which allows attackers to upload malicious executables and take control of sites. Patchstack says it blocked such uploads, stopping thousands of attempts by cybercriminals. The vulnerability was fixed in version 1.7.14.
  • CVE-2024-8353: A vulnerability (PHP object injection) in the GiveWP plugin (100,000+ installations) could allow an attacker to take complete control of a WordPress site. Patchstack filters malicious patterns and prevented hundreds of malicious attempts. The vulnerability was fixed in version 3.16.2.
  • CVE-2024-25600 : A remote code execution found in the Bricks WordPress theme vulnerability (30,000+ installations). It allows unauthorized PHP execution via the bricks/v1/render_element REST route. Weak permission checks and an exposed nonce enable the attack. The first signs of exploitation were detected by both Patchstack and Wordfence in February 2024. The vulnerability was fixed in version 1.9.6.1 of the theme.

See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites

It should be noted that attempts to exploit the above WordPress vulnerabilities do not always lead to successful breaches, as many of these checks are blocked before they can cause any harm. However, since not all websites are protected, there is always a risk that hackers may eventually find a way to successfully breach them.

WordPress: The vulnerabilities most exploited by hackers in Q1 2025

WordPress Security

WordPress website security requires a multi-pronged approach to protect against potential threats. One key strategy includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.

It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.

See also: Vulnerability in Chaty Pro plugin puts WordPress sites at risk

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS