HomeScience and technologyDigital technologyWebsites using WordPress need to remove these 2 plugins

Websites using WordPress need to remove these 2 plugins


According to The HackerNew, two plugins for WordPress, Malware Scanner and Web Application Firewall of miniOrage, are experiencing a serious security error, CVE-2024-2172, discovered by Stiofan, with a critical error score of 9,8 on the system's 10-point scale. CVSS security vulnerability scoring.

The error has a widespread impact because even though the developer was removed from the WordPress application store on March 7.3.2024, 10.000, they can still have an impact because Malware Scanner has recorded installations and activities on up to 300 websites. , while with Web Application Firewall it is XNUMX.

Wordfence said the vulnerability is the result of a lack of checks in the plugin's code, allowing an unauthenticated attacker to arbitrarily update any user's password and escalate privileges to admin. members, potentially leading to a complete compromise of the website.

Websites using WordPress need to remove these 2 plugins - Photo 1.

As the most popular CMS platform, WordPress is a target for hackers to exploit

When having administrative rights, hackers can easily download additional plugins, malicious zip files containing backdoors, and modify website posts to redirect users to other malicious websites.

Previously, a similar plugin, RegistrationMagic, was reported with error code CVE-2024-1991 and CVSS score 8.8, which is also a high severity privilege escalation vulnerability. This plugin has also been downloaded and installed more than 10.000 times.

WordPress is a famous open source content management system (CMS), widely used around the world. The ease of installing, posting and managing content on this CMS platform makes WordPress the ideal platform for all types of websites such as online stores, portals, discussion forums... According to w3techs, this CMS platform is currently chosen by 43,1% of websites in the world.



Source link

Same topic

Highlights

New Posts

Same author

Much read

Same category

New Posts

"Connecting strength - Connecting love"

On March 23, at Luong Yen Secondary School (Hai Ba Trung District, Hanoi), the Children's Media Center (Ho Chi Minh Communist Youth Union Central Committee) coordinated with Save the Children (SCI) to organize Media program with the theme "Connecting strength - Connecting love". The event was organized by the members themselves...

Once an environmental sanitation worker, Den Vau became a typical young face

On the evening of March 23, the Ho Chi Minh Communist Youth Union Central Committee and the Vietnam Youth Talent Support Fund held an award ceremony for Outstanding Young Vietnamese Faces of 3. The Council considered and awarded the Outstanding Young Vietnamese Faces of the Year Award. 2023 has selected 2023 best faces to award...
18:51:29

Dalat purple phoenix - the beauty of nostalgia

Coming to Da Lat on this occasion, visitors will admire the purple color of poinciana flowers dyeing all the roads and street corners. This is a typical flower of Da Lat with a beauty that evokes memories and dreams, making people and tourists everywhere ecstatic. Origin of...

New Posts