June 25, 2024
Sin comentarios
Multiple WordPress plugins have been maliciously modified to include a backdoor making it possible to create administrator accounts in order to take control of the website.
Habitually, These new non-legitimate accounts are called “Options” or “PluginAuth” with the information leaked to a malicious IP address, Plugin-focused:
- Social Warfare 4.4.6.4 – 4.4.7.1 (Update with solution: 4.4.7.3)
- Blaze Widget 2.2.5 – 2.5.2
- Wrapper Link Element 1.0.2 – 1.0.3
- Contact Form 7 Multi-Step Addon 1.0.4 – 1.0.5
- Simply Show Hooks 1.2.1
It is recommended to update to the latest versions of such plugins to avoid exposure to potential attacks.
Fountain: TheHackerNews
More news
New wave of scams using AI-cloned voices
Read more »
Una brecha en la Comisión Europea salpica unas treinta instituciones
Read more »
Un ciberataque expone datos y entradas de aficionados del FC Ajax
Read more »
Michelin suffers a data exfiltration
Read more »
Atacan un centro de investigación nuclear en Polonia
Read more »