❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

24 June 2024 at 17:00
Stylized illustration a door that opens onto a wall of computer code.

Enlarge (credit: Getty Images)

WordPress plugins running on as many as 36,000 websites have been backdoored in a supply-chain attack with unknown origins, security researchers said on Monday.

So far, five plugins are known to be affected in the campaign, which was active as recently as Monday morning, researchers from security firm Wordfence reported. Over the past week, unknown threat actors have added malicious functions to updates available for the plugins on WordPress.org, the official site for the open source WordPress CMS software. When installed, the updates automatically create an attacker-controlled administrative account that provides full control over the compromised site. The updates also add content designed to goose search results.

Poisoning the well

β€œThe injected malicious code is not very sophisticated or heavily obfuscated and contains comments throughout making it easy to follow,” the researchers wrote. β€œThe earliest injection appears to date back to June 21st, 2024, and the threat actor was still actively making updates to plugins as recently as 5 hours ago.”

Read 6 remaining paragraphs | Comments

Understanding the RCE Vulnerabilities in WordPress Plugins

10 June 2024 at 04:00

Β  Imagine handing over the controls of your website to someone you don’t trust – that’s the risk of RCE vulnerabilities in WordPress. Attackers can modify website content, inject spammy content, and spread malware, infecting site visitors. To avoid any errors, it’s crucial to ensure that all your plugins and themes are compatible with the […]

The post Understanding the RCE Vulnerabilities in WordPress Plugins appeared first on TuxCare.

The post Understanding the RCE Vulnerabilities in WordPress Plugins appeared first on Security Boulevard.

❌
❌