Stories
Slash Boxes
Comments

SoylentNews is people

posted by janrinok on Sunday April 02, @06:38PM   Printer-friendly

Hackers exploit WordPress plugin flaw that gives full control of millions of sites

Hackers have been exploiting a critical vulnerability in a popular WordPress plugin called 'Loginizer' that allows them to take full control of affected sites. The vulnerability, tracked as CVE-2023-27728, is a SQL injection flaw that allows attackers to insert malicious code into the site's database, giving them access to sensitive data and the ability to execute remote code. Loginizer is installed on millions of WordPress sites, and the vulnerability affects all versions up to and including 1.6.5. The plugin is designed to provide security features such as two-factor authentication and brute-force protection.

Security researchers have identified multiple hacking groups actively exploiting the vulnerability in recent weeks. The attackers are scanning the internet for WordPress sites that have the vulnerable plugin installed and are using automated tools to inject malicious code into the site's database. Once a site is compromised, the attackers can use it for various malicious purposes, such as stealing user data or distributing malware.

The plugin's developers have released a patch for the vulnerability, and WordPress site owners are advised to update their installations immediately. However, given the widespread use of the plugin, it is likely that many sites remain vulnerable to exploitation. Loginizer is just one of many WordPress plugins that have been found to have security flaws in recent years, highlighting the importance of regular security updates and monitoring for site owners.


Original Submission

 
This discussion was created by janrinok (52) for logged-in users only, but now has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 4, Funny) by bloodnok on Sunday April 02, @11:46PM

    by bloodnok (2578) on Sunday April 02, @11:46PM (#1299477)

    . . . from a threatened Slashdot UI change that never materialized. . .

    Never materialized?

    You mean I'm a refugee from an event that never happened? The last 9 years were based on a misunderstanding? I could have used the green site after all? Fuck beta meant nothing?

    Oh crap!

    __
    The Major

    Starting Score:    1  point
    Moderation   +2  
       Funny=2, Total=2
    Extra 'Funny' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   4