A critical vulnerability, which has been discovered in one of the most popular plugins of the WordPress content management platform, puts more than one million websites at risk.
The vulnerability affects most versions of the "Wettable Powder Slimstat" (WP-Slimstat) plugin , which is one of the most popular WordPress plugins for statistical website analysis.
At this time, there are more than 70 million websites on the internet running WordPress, while more than 1.3 million of them use "WP-Slimstat", making it one of the powerful plugins for providing real time web analytics.
All versions of WP-Slimstat released before version 3.9.6 contain an easily identifiable "secret" key, which is used to sign data sent to and from end-user computers, security firm Sucuri.
If the vulnerable "secret" key is cracked, an attacker could perform an SQL injection against the website in order to steal highly sensitive information from the victim's database, including encrypted passwords and the encryption keys used to remotely administer the websites.
«If your website uses a vulnerable version of the plugin, you are at risk,» wrote Marc-Alexandre Montpas, researcher at Sucuri.
«The successful exploitation of this bug could lead to Blind SQL Injection attacks, which means that an attacker could steal sensitive information from your database, including the username (hashed), passwords and, under certain conditions, the WordPress Secret Keys – which could lead to a full takeover of the website.»
Users running WordPress sites and who have installed WP-Slimstat must upgrade immediately to the latest version in order to protect their site from this dangerous vulnerability.

