WordPress plugin flaw lets you take over entire sites

Discussion in 'other security issues & news' started by guest, Feb 11, 2019.

  1. guest

    guest Guest

    200K sites with buggy WordPress plugin exposed to wipe attacks
    May 28, 2020
    https://www.bleepingcomputer.com/ne...ggy-wordpress-plugin-exposed-to-wipe-attacks/
    Wordfence: High Severity Vulnerabilities in PageLayer Plugin Affect Over 200,000 WordPress Sites
     
  2. SAustn2

    SAustn2 Registered Member

    I take it "new" doesn't always carry the association "and improved".
     
  3. guest

    guest Guest

    Advertising Plugin for WordPress Threatens Full Site Takeovers
    Thousands of vulnerable websites need to apply the patch to avoid RCE
    July 8, 2020
    https://threatpost.com/advertising-plugin-wordpress-full-site-takeovers/157283/
    Wordfence: Critical Vulnerabilities Patched in Adning Advertising Plugin
     
  4. guest

    guest Guest

    SEO plugin for WordPress would run arbitrary JavaScript inputs instead of scrubbing them
    XSS vuln could hijack websites so update your All in One pack
    July 17, 2020
    https://www.theregister.com/2020/07/17/all_in_one_seo_pack_javascript_sanitisation_vuln
    Wordfence: 2 Million Users Affected by Vulnerability in All in One SEO Pack
     
  5. guest

    guest Guest

    Critical Wordpress plugin bug lets hackers take over hosting account
    July 28, 2020
    https://www.bleepingcomputer.com/ne...n-bug-lets-hackers-take-over-hosting-account/
    Wordfence: Critical Arbitrary File Upload Vulnerability Patched in wpDiscuz Plugin
     
  6. guest

    guest Guest

    Newsletter plugin bugs let hackers inject backdoors on 300K sites
    August 3, 2020
    https://www.bleepingcomputer.com/ne...s-let-hackers-inject-backdoors-on-300k-sites/
    Wordfence: Newsletter Plugin Vulnerabilities Affect Over 300,000 Sites
     
  7. guest

    guest Guest

    Critical Flaws in WordPress Quiz Plugin Allow Site Takeover
    August 14, 2020
    https://threatpost.com/critical-flaws-wordpress-quiz-plugin-site-takeover/158379/
    Wordfence: Critical Vulnerabilities Patched in Quiz and Survey Master Plugin
     
  8. guest

    guest Guest

    WordPress WooCommerce stores under attack, patch now
    August 21, 2020
    https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/
    WebARX: Multiple Vulnerabilities In Discount Rules for WooCommerce Plugin
     
  9. guest

    guest Guest

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites
    Flaw is in File Manager, a plugin with more than 700,000 users; 52% are affected
    September 2, 2020

    https://arstechnica.com/information...itical-flaw-affecting-350000-wordpress-sites/
    Wordfence: 700,000 WordPress Users Affected by Zero-Day Vulnerability in File Manager Plugin
     
  10. guest

    guest Guest

    Hackers are fighting a war over 300K vulnerable WordPress sites
    September 10, 2020
    https://www.bleepingcomputer.com/ne...g-a-war-over-300k-vulnerable-wordpress-sites/
    Wordfence:
    Millions of Sites Targeted in File Manager Vulnerability Attacks (September 4, 2020)
    Attackers Fight for Control of Sites Targeted in File Manager Vulnerability (September 10, 2020)
     
  11. guest

    guest Guest

    Stubborn WooCommerce Plugin Bugs Get Third Patch
    Users of the Discount Rules for WooCommerce WordPress plugin are urged to apply a third and (hopefully) final patch
    September 18, 2020

    https://threatpost.com/woocommerce-plugin-bug-allows-site-takeover/159364/
    Wordfence: High-Severity Vulnerabilities Patched in Discount Rules for WooCommerce
     
  12. guest

    guest Guest

    Vulnerability in WordPress plugin TI WooCommerce Wishlist could allow full site takeover
    Flaw in popular add-on allows any logged-in customer to achieve admin status
    October 19, 2020

    https://portswigger.net/daily-swig/...merce-wishlist-could-allow-full-site-takeover
     
  13. guest

    guest Guest

    Critical Privilege Escalation Vulnerabilities Affect 100K Sites Using Ultimate Member Plugin
    November 9, 2020
    https://www.wordfence.com/blog/2020...fect-100k-sites-using-ultimate-member-plugin/
    Threatpost: Ultimate Member Plugin for WordPress Allows Site Takeover
     
  14. guest

    guest Guest

    Easy WP SMTP WordPress Plugin Vulnerability Let Hackers Takeover Admin Accounts
    December 12, 2020
    https://techdator.net/easy-wp-smtp-...rability-let-hackers-takeover-admin-accounts/
    WordPress Easy WP SMTP plugin fixed zero-day vulnerability
     
  15. guest

    guest Guest

    WordPress plugin with 5 million installs has a critical vulnerability
    December 17, 2020
    https://www.bleepingcomputer.com/ne...illion-installs-has-a-critical-vulnerability/
    Astra: Unrestricted File Upload Vulnerability found in Contact Form 7, update immediately (5 million+ sites affected)
     
  16. guest

    guest Guest

    Critical WordPress-Plugin Bug Found in ‘Orbit Fox’ Allows Site Takeover
    January 13, 2021
    https://threatpost.com/orbit-fox-wordpress-plugin-bugs/163020/
    Wordfence: Multiple Vulnerabilities Patched in Orbit Fox by ThemeIsle Plugin
     
  17. guest

    guest Guest

    WordPress File Management Plugin Riddled with Critical Bugs
    The bugs allow a range of attacks on websites, including deleting blog pages and remote code execution
    July 12, 2021
    https://threatpost.com/frontend-file-manager-wordpress-bugs/167687/
    NinTechNet: WordPress Frontend File Manager plugin fixed multiple critical vulnerabilities
     
  18. guest

    guest Guest

    Remote Code Execution Flaws Patched in WordPress Download Manager Plugin
    July 30, 2021
    https://www.securityweek.com/remote-code-execution-flaws-patched-wordpress-download-manager-plugin
    Wordfence: Multiple Vulnerabilities Patched in WordPress Download Manager
     
  19. guest

    guest Guest

    XSS Bug in SEOPress WordPress Plugin Allows Site Takeover
    August 16, 2021
    https://threatpost.com/xss-bug-seopress-wordpress-plugin/168702/
    Wordfence: XSS Vulnerability Patched in SEOPress Affects 100,000 sites
     
  20. guest

    guest Guest

    Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers
    October 13, 2021
    https://threatpost.com/brizy-wordpress-plugin-exploit-site-takeovers/175463/
    Wordfence: Multiple Vulnerabilities in Brizy Page Builder Plugin Allow Site Takeover
     
  21. guest

    guest Guest

    Injection vulnerabilities in popular WordPress plugin could expose credentials, allow admin access
    Fastest Cache is used by more than one million websites
    October 15, 2021

    https://portswigger.net/daily-swig/...n-could-expose-credentials-allow-admin-access
     
  22. guest

    guest Guest

    Brutal WordPress plugin bug allows subscribers to wipe sites
    October 26, 2021
    https://www.bleepingcomputer.com/ne...-plugin-bug-allows-subscribers-to-wipe-sites/
    Wordfence: Site Deletion Vulnerability in Hashthemes Plugin
     
  23. guest

    guest Guest

    Ironic twist: WP Reset PRO bug lets hackers wipe WordPress sites
    November 10, 2021
    https://www.bleepingcomputer.com/ne...et-pro-bug-lets-hackers-wipe-wordpress-sites/
     
  24. guest

    guest Guest

    Hundreds of WordPress sites defaced in fake ransomware attacks
    November 16, 2021
    https://therecord.media/hundreds-of-wordpress-sites-defaced-in-fake-ransomware-attacks/
    Sucuri: Fake Ransomware Infection Spooks Website Owners
     
  25. guest

    guest Guest

    Server-side vulnerabilities in Concrete CMS put thousands of websites under threat
    November 16, 2021
    https://portswigger.net/daily-swig/...te-cms-put-thousands-of-websites-under-threat
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice