SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    WordPress Sites Attacked in Their Millions
Date    Monday September 14 2020, @03:41AM
Author    Fnord666
Topic   
from the one-more-for-the-record dept.
https://soylentnews.org/article.pl?sid=20/09/13/1829246

upstart writes in with an IRC submission for RandomFactor of yet another WordPress plugin vulnerability:

WordPress Sites Attacked in Their Millions:

Millions of WordPress sites are being probed in automated attacks looking to exploit a recently discovered plugin vulnerability, according to security researchers.

Wordfence, which itself produces a plugin for the platform, revealed news of the zero-day bug at the start of September. It affects File Manager which, as the name suggests, is a plugin that helps users to manage files on their WordPress sites.

[...] The vulnerability itself could allow a remote, unauthenticated user to execute commands and upload malicious files on a target site. [Wordfence’s Ram] Gall therefore urged users to patch the issue promptly by installing the latest version of the plug, v6.9.

"If you are not actively using the plugin, uninstall it completely," he added. "Due to the breadth of file management functionality this plugin provides a user within the wp-admin dashboard, we recommend uninstalling the plugin when it is not actively being used."

[Ed Note: Wordfence sells a product intended to protect WordPress sites]


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "WordPress Sites Attacked in Their Millions" - https://www.infosecurity-magazine.com/news/wordpress-sites-attacked-in-their/
  3. "revealed news" - https://www.wordfence.com/blog/2020/09/700000-wordpress-users-affected-by-zero-day-vulnerability-in-file-manager-plugin/
  4. "he added" - https://www.wordfence.com/blog/2020/09/millions-of-sites-targeted-in-file-manager-vulnerability-attacks/
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=43371

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, WordPress Sites Attacked in Their Millions on 2024-04-19 16:45:19