Vietnam.vn - Nền tảng quảng bá Việt Nam

Security flaw puts 4 million WordPress websites at risk.

Báo Thanh niênBáo Thanh niên24/10/2023


Writing on their blog, Wordfence's threat intelligence team announced they were responsible for disclosing a cross-site code injection (XSS) vulnerability in the LiteSpeed ​​Cache plugin. This popular add-on has been installed on over 4 million WordPress websites. This security vulnerability allows hackers with contributor privileges to inject malicious scripts using shortcodes.

LiteSpeed ​​Cache is a WordPress website speed-up plugin that uses caching and supports server-level optimization. This add-on provides a shortcode that can be used to cache blocks using Edge Side technology when added to WordPress.

However, Wordfence stated that the plugin's shortcode implementation is insecure, allowing the injection of arbitrary scripts into these pages. A vulnerability check revealed that the shortcode method does not adequately validate input and output. This allows threat actors to carry out XSS attacks. Once embedded in a page or post, the script executes every time a user accesses it.

Lỗi bảo mật khiến 4 triệu website WordPress gặp nguy hiểm - Ảnh 1.

LiteSpeed ​​Cache is a popular speed-boosting plugin for the WordPress platform.

Although this vulnerability requires the contributor's account to be compromised or the user to register as a contributor, Wordfence says attackers could steal sensitive information, manipulate website content, attack administrators, edit files, or redirect visitors to malicious websites.

Wordfence stated that it contacted the LiteSpeed ​​Cache development team on August 14th. The patch was deployed on August 16th and released to WordPress on October 10th. Users now need to update LiteSpeed ​​Cache to version 5.7 to completely fix this security vulnerability. Although dangerous, Wordfence's built-in Cross-Site Scripting protection helped prevent this exploit.



Source link

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

Admire the dazzling churches, a 'super hot' check-in spot this Christmas season.
The 150-year-old 'Pink Cathedral' shines brightly this Christmas season.
At this Hanoi pho restaurant, they make their own pho noodles for 200,000 VND, and customers must order in advance.
The Christmas atmosphere is vibrant on the streets of Hanoi.

Same author

Heritage

Figure

Enterprise

The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.

News

Political System

Destination

Product