Vietnam.vn - Nền tảng quảng bá Việt Nam

A security vulnerability puts 200,000 WordPress websites at risk.

Báo Thanh niênBáo Thanh niên02/07/2023


According to The Hacker News , the vulnerability, with tracking code CVE-2023-3460 (CVSS score 9.8), exists in all versions of the Ultimate Member plugin (extension), including the latest version (2.6.6) released on June 29, 2023.

Ultimate Member is a popular plugin that helps create user profiles and communities on WordPress websites. This utility also provides account management features.

WPScan, a WordPress security company, stated that this security vulnerability is very serious, allowing attackers to exploit it to create new user accounts with administrative privileges, giving hackers complete control over affected websites.

Lỗ hổng bảo mật khiến 200.000 website WordPress gặp nguy hiểm - Ảnh 1.

Ultimate Member is a popular plugin used by over 200,000 websites.

Details about the vulnerability were withheld due to concerns about abuse. Security experts from Wordfence described that although the plugin has a list of banned keys that users cannot update, there are simple ways to bypass the filters, such as using forward slashes or character encoding in the values ​​provided in versions of the plugin.

This security vulnerability was disclosed after reports emerged of fake administrator accounts being added to affected websites. This prompted plugin developers to release partial fixes in versions 2.6.4, 2.6.5, and 2.6.6. A new update is expected to be released in the coming days.

Ultimate Member stated in its latest release that a privilege escalation vulnerability, exploited through UM Forms, allows unauthorized individuals to create administrator-level WordPress users. However, WPScan pointed out that the patches are incomplete and several methods to bypass them have been found, meaning the vulnerability remains exploitable.

The vulnerability is being exploited to register new accounts under the names apads, se_brutal, segs_brutal, wpadmins, wpengine_backup, and wpenginer to upload malicious plugins and themes through the website's admin panel. Ultimate Member users should disable plugins until this security vulnerability is fully patched.



Source link

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

Admire the dazzling churches, a 'super hot' check-in spot this Christmas season.
The 150-year-old 'Pink Cathedral' shines brightly this Christmas season.
At this Hanoi pho restaurant, they make their own pho noodles for 200,000 VND, and customers must order in advance.
The Christmas atmosphere is vibrant on the streets of Hanoi.

Same author

Heritage

Figure

Enterprise

The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.

News

Political System

Destination

Product