<div class="separator"><a href="https://thehackernews.com/images/-HGTTmFGT_Xg/YLdVHBAUTVI/AAAAAAAACt4/tB2fDggPt-cYTf59dPOV2vQGyaYls4iCwCLcBGAsYHQ/s0/wordpress-plugin.jpg"></a></div> <p>Fancy Product Designer, a WordPress plugin installed on over 17,000 sites, has been discovered to contain a critical file upload vulnerability that’s being actively exploited in the wild to upload malware onto sites that have the plugin installed.</p> <p>Wordfence’s threat intelligence team, which discovered the flaw, said it reported the issue to the plugin’s developer on May 31. While the flaw has been acknowledged, it’s yet to be addressed.</p> <p>Fancy Product Designer is a tool that enables businesses to offer customizable products, allowing customers to design any kind of item ranging from T-shirts to phone cases by offering the ability to upload images and PDF files that can be added to the products.</p> <div class="ad_two clear"><center class="cf"><a href="https://go.thn.li/1-300-4" rel="nofollow noopener sponsored" target="_blank" title="password auditor"><img alt="password auditor" class="lazyload" src="https://thehackernews.com/images/-J2_tCNGDMKA/YHc_zdc4MhI/AAAAAAAA3wo/gfFnHKGV_gcrTkZ3sOMoDg5N-wg_cKOGQCLcBGAsYHQ/s300-e100/thn-300-4.png"></a></center></div> <p>“Unfortunately, while the plugin had some checks in place to prevent malicious files from being uploaded, these checks were insufficient and could easily be bypassed, allowing attackers to upload executable PHP files to any site with the plugin installed,” Wordfence <a href="https://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/" rel="noopener" target="_blank">said</a> in a write-up published on Tuesday.</p> <div class="separator"><a href="https://thehackernews.com/images/-WIUOSJby35c/YLdLFewwX2I/AAAAAAAACtw/rqISXIaegHAhy1_pmWyUVzvQATuATdSIgCLcBGAsYHQ/s0/wordpress-hacking.jpg"><img alt="WordPress Plugin" border="0" data-original-height="466" data-original-width="728" src="https://thehackernews.com/images/-WIUOSJby35c/YLdLFewwX2I/AAAAAAAACtw/rqISXIaegHAhy1_pmWyUVzvQATuATdSIgCLcBGAsYHQ/s728-e1000/wordpress-hacking.jpg" title="WordPress Plugin"></a></div> <p>Armed with this capability, an attacker can achieve remote code execution on an affected website, allowing full site takeover, the researchers noted. Wordfence has not shared the technical specifics of the vulnerability as it’s under active attack.</p> <p>Wordfence said that the critical zero-day could be exploited in select configurations even if the plugin has been deactivated, urging users to completely uninstall Fancy Product Designer until a patched version becomes available.</p> <p>This is far from the first time Wordfence has disclosed severe issues in WordPress plugins. In December 2017, a hidden backdoor in <a href="https://thehackernews.com/2017/12/wordpress-security-plugin.html" rel="noopener" target="_blank">BestWebSoft</a> captcha plugin was found to affect 300,000 sites.</p> <p>Then earlier this year, the researchers revealed <a href="https://thehackernews.com/2021/03/flaws-in-two-popular-wordpress-plugins.html" rel="noopener" target="_blank">vulnerabilities</a> in Elementor and WP Super Cache that, if successfully exploited, could allow an attacker to run arbitrary code and take over a website in certain scenarios.</p> <p></p> <p>The post <a rel="nofollow" href="https://patabook.com/technology/2021/06/02/hackers%e2%80%8c-%e2%80%8cactively%e2%80%8c-%e2%80%8cexploiting%e2%80%8c-%e2%80%8c0-day%e2%80%8c-%e2%80%8cin-wordpress-plugin-installed-on-over-%e2%80%8c17000%e2%80%8c-%e2%80%8csites/">Hackers‌ ‌Actively‌ ‌Exploiting‌ ‌0-Day‌ ‌in WordPress Plugin Installed on Over ‌17,000‌ ‌Sites</a> appeared first on <a rel="nofollow" href="https://patabook.com/technology">Patabook Technology</a>.</p>
source https://patabook.com/blogs/96648/Hackers-Actively-Exploiting-0-Day-in-WordPress-Plugin-Installed-on
Subscribe to:
Post Comments (Atom)
Antifa Groups Charged with Violently Countering California ‘Patriot March’
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
source https://www.todayonline.com/world/portugal-urged-seek-international-help-covid-19-deaths-hit-record
-
source https://www.todayonline.com/world/five-injured-hundreds-evacuated-after-massive-blaze-indonesia-oil-refinery
No comments:
Post a Comment