This week, the WordPress CMS (content management system) is causing extra hassles for administrators and WordPress users because of a couple of discrete but worrisome security issues in the platform’s add-ons.
The first problem is with the AdSanity plugin. The second issue is a standard supply-chain exploit, in which cybercriminals hacked 53 WordPress plugins and 40 AccessPress Templates to insert a webshell into them.
As a result, every website using one of the vulnerable add-ons is susceptible to RCE & full control.
Researchers discovered that an exploit might be carried out by simply placing an index.php script within a.ZIP file to be published. Additionally, the hacker can attach JavaScript code files, which might be used to attack the administrator reading the post.
Anyone using WordPress, according to Roy Horev, CEO and co-founder of Vulcan Cyber, “should be smart enough to realize how to stay at the forefront of their security upgrades.”
So, we recommend performing a thorough inspection of WordPress and its plugins at least once a quarter and installing the latest version appropriately as soon as new versions are released.
#wordpress #Malware #Attacks #Cybersecurity #News #AccessPress

Share: