HomeNews & updatesCritical vulnerability in popular WordPress plugin exposes millions of sites to hacking...

Critical vulnerability in popular WordPress plugin exposes millions of sites to hacking – SiliconANGLE News

UPDATED 21:01 EST / APRIL 14 2022
by Duncan Riley
A critical vulnerability in a highly popular WordPress plugin has exposed millions of websites to hacking.
Discovered by researchers at Plugin Vulnerabilities and detailed April 12, the vulnerability was found in Elementor, a WordPress plugin that allows users to build websites with more than 5 million active installations. The vulnerability was found in version 3.6.0 of the plugin, introduced on March 22, with about a third of the sites using Elemantor to run the vulnerable version when the vulnerability was found.
The vulnerability is caused by an absence of a critical access check in one of the plugin’s files, which is loaded on every request, even if users are not logged in. Because the check does not occur, access to the file and hence the plugin is open to all and sundry, including bad actors.
Exploiting the vulnerability opens the door for anyone to make changes to the site, including uploading arbitrary files. As a result, hackers could exploit the vulnerability for remote code execution and takeover of a site running the plugin. “Based on just what we saw in our very limited checking, we would recommend not using this plugin until it has had a thorough security review and all issues are addressed,” the researchers noted.
The vulnerability has since been addressed in the latest update to Elementor version 3.6.3. Naturally, anyone running a WordPress install with Elementor  3.6.0 to 3.6.2 is encouraged to update to the latest version to address the critical vulnerability.
“WordPress powers as much as a third of all websites on the Internet, including some of the most highly trafficked sites and a large percentage of e-commerce sites, so why aren’t they better equipped to protect against attack?”  Pravin Madhani, co-founder and chief executive of application security platform provider K2 Cyber Security Inc., told SiliconANGLE. “In particular, RCE is one of the most dangerous flaws because it gives the attacker the ability to run almost any code on the hacked site.”
Madhani explained that traditional application security tools like Web Application Firewalls have difficulty in dealing with RCE attacks because they rely on understanding a past RCE attack or signature in order to detect a new zero-day or undiscovered attack.
“For maximum protection, organizations using WordPress should make sure they use security in-depth, including application, network and system-level security,” Madhani added. “Finally, the simplest thing any organization can do to help reduce vulnerabilities is to keep their code — WordPress, plugins, SQL server-MySQL/MariaDB, web server-NGINX/Apache — up to date and patched.”
Click here to join the free and open Startup Showcase event.
We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.
Click here to join the free and open Startup Showcase event.
Equinix debuts highly distributed, low-latency bare metal deployment option for VMware Cloud
VMware targets remote workers with beefed-up SD-WAN client
PitchBook: Late-stage venture capital valuations fall from 2021 highs
Twitter users will get banned for impersonating others if they don’t label their accounts as parody
Exotanium raises $12M to optimize cloud efficiency while reducing costs by up to 90%
Weak guidance sends Five9’s stock down in after-hours trading
Equinix debuts highly distributed, low-latency bare metal deployment option for VMware Cloud
CLOUD – BY MIKE WHEATLEY . 2 HOURS AGO
VMware targets remote workers with beefed-up SD-WAN client
CLOUD – BY PAUL GILLIN . 3 HOURS AGO
PitchBook: Late-stage venture capital valuations fall from 2021 highs
EMERGING TECH – BY DUNCAN RILEY . 6 HOURS AGO
Twitter users will get banned for impersonating others if they don’t label their accounts as parody
POLICY – BY JAMES FARRELL . 9 HOURS AGO
Exotanium raises $12M to optimize cloud efficiency while reducing costs by up to 90%
CLOUD – BY MIKE WHEATLEY . 9 HOURS AGO
Weak guidance sends Five9’s stock down in after-hours trading
CLOUD – BY MIKE WHEATLEY . 10 HOURS AGO
Forgot Password?
Like Free Content? Subscribe to follow.

source

- Advertisment -


Most Popular

- Advertisment -