Hackers target critical vulnerability in WordPress plugin to compromise websites: Report 

The Hindu Bureau The Hindu Bureau | 04-27 00:20

Hackers are using a critical vulnerability in the WP Automatic, a plugin used by more than 30,000 websites in WordPress. The vulnerability is being exploited to create user accounts with administrative privileges and plant backdoors in the websites for long-term access.

The critical vulnerability was first disclosed by researchers and impacts WP Automatic versions before 3.9.2.0. The vulnerability exists in the plugin’s user authentication mechanism, allowing threat actors to bypass security, , a report from Bleeping Computer said.

Hackers can then use specially crafted queries to create administrator accounts on the target website compromising its security, as well as the security of visitors.

Since the vulnerability was identified, researchers have observed more than 5.5million attacks trying to leverage the vulnerability. Hackers have also been found to change the name of vulnerable files to ensure others cannot use the vulnerability to gain administrative privileges.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

Hackers have also been found to install additional plugins on the compromised website allowing them to upload files and edit existing codes.

Website administrators can check for signs that hackers took over their websites by looking for the presence of an admin account starting with “xtw” and files named web.php and index.php, which are used as backdoors by hackers.

Website administrators are also advised to update the WP Automatic plugin to its version to avoid the vulnerability from being exploited. Additionally, administrators should also create backups of their site so they can install clean copies quickly in case of a compromise.

Disclaimer: The copyright of this article belongs to the original author. Reposting this article is solely for the purpose of information dissemination and does not constitute any investment advice. If there is any infringement, please contact us immediately. We will make corrections or deletions as necessary. Thank you.


ALSO READ

Ola Electric responds to ARAI notice, says prices of S1 X 2 kWh scooter unchanged

Ola Electric provided an invoice dated October 6, showing a INR 5,000 discount given to customers, a...

Hyundai Motor IPO’s off to a slow start

Around 35% of the total shares in the offering are reserved for retail investors, while QIBs and NII...

Under fire, Ola Electric taps EY India to get back on track

Close to a dozen executives from EY came on-board at Ola Electric a few weeks ago on deputation for ...

Tata Motors secures 5-star BNCAP safety ratings for Nexon, Curvv, and EV models in latest crash tests

Tata Curvv.EV BNCAP testTata Motors did it again! Tata Motors has once again secured 5 star rating i...

India needs to step up manufacturing to meet Viksit Bharat goal: Volvo Grp India MD

Volvo Group India Managing Director and President, Kamal Bali. The manufacturing sector is a weak li...

Dollar pullback to help Indian rupee, weak risk appetite to weigh

Investors are now nearly certain that the U.S. Federal Reserve will deliver a 25-basis-point rate cu...