Site icon WinCert

Critical WordPress plugin vulnerability exposes million sites to attacks

<p>WordPress security experts&comma; Wordfence&comma; uncovered a significant vulnerability&comma; CVE-2023-6933&comma; in the Better Search Replace WordPress plugin&period; This flaw&comma; an object injection vulnerability&comma; affected all versions of the plugin&comma; including the recent 1&period;4&period;5 release&period; The plugin has been widely downloaded over a million times and assists admins in database searches thus replacing tasks during site migrations&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-1560" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2015&sol;07&sol;wp&period;png" alt&equals;"" width&equals;"720" height&equals;"340" &sol;><&sol;p>&NewLine;<p>Exploiting the vulnerability requires specific conditions&colon; the website or theme must contain the Property Oriented Programming &lpar;POP&rpar; chain&period; Once triggered&comma; this vulnerability enables attackers to execute malicious actions&comma; including code execution&comma; data access&comma; file manipulation&comma; and inducing a perpetual denial of service&period;<&sol;p>&NewLine;<p>Within just 24 hours of discovery&comma; Wordfence reported blocking over 2&comma;500 attacks&period; Users are strongly advised to update to version 1&period;4&period;5&period; However&comma; the WordPress&period;org website indicates that four in five installations are of version 1&period;4&period; while missing statistics for minor releases&period;<&sol;p>&NewLine;<p>And even though WordPress as a website builder is generally considered safe&comma; the same cannot be said for its plugins&period; Many&comma; often developed by small&comma; non-commercial teams&comma; lack proper maintenance&comma; making them potential gateways for security breaches and malicious activity&period; To stay secure make sure to update your plugins regularly&period;<&sol;p>&NewLine;

Exit mobile version