Security

Patch your WordPress plugins: Scum are right now hijacking blogs

Unless of course your site is so dull that a little hacker defacement will cheer it up


The plugin gurus at WordFence have this week found three critical security holes in third-party WordPress extensions that are being actively exploited by hackers to take over websites.

The team was investigating a number of hacking attacks that looked unusual and back-traced the intrusions to a PHP object injection vulnerability. This programming cockup was present in three plugins for the publishing platform WordPress, and patches to close the hole have now been prepared for the following code:

There are possibly other plugins affected, too.

The flaw can be exploited to force an unpatched website to pull in a remote malicious file and save it on the host machine, giving miscreants a means to install a backdoor on the box. For the Flickr plugin, it was even less complicated: just send the malicious code in a POST request to the site’s root URL and it would install and run it.

Once the attack code is activated, an intruder can take complete control of the site in a matter of minutes and do with it what they like. Script kiddies like the Daesh-bag hacking groups should find this very useful for defacing unpatched websites.

Thankfully these aren't massively popular apps with barely 20,000 users so far – but that's still potentially 20,000 websites that can be used as a starting point for more nefarious activities. Administrators are advised to either remove and reinstall the software with the latest version, or simply upgrade. ®

Send us news
12 Comments

Turns out teaching criminals to write web code keeps them out of prison

The software redemption

Throwflame launches fire-spitting robo-dog from Hell

The Thermonator can be yours for just $9,420

Microsoft and Amazon's AI ambitions spark regulatory rumble

Tech giants confident everything's in order

BMW calls for vendor openness in quest to mine its own processes

'Software companies try to extend their reach and their usage, but this can't be by locking in users,' says process mining lead

Forget the AI doom and hype, let's make computers useful

Machine learning has its place, just not in ways that suits today's hypesters

Indian bank’s IT is so shabby it’s been banned from opening new accounts

After two years of warnings, and outages, regulators ran out of patience with Kotak Mahindra Bank

Samsung shows off battery tech it says will see you gone in nine minutes

Might help to set spluttering EV market on fire. Won't catch fire thanks to built-in vents

IBM to acquire Hashi for $6.4 billion, hopes it will boost software biz and Red Hat

Investors want to know what Big Blue is smoking after growth disappoints

Australia’s spies and cops want ‘accountable encryption’ - aka access to backdoors

And warn that AI is already being used by extremists to plot attacks

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

Don't get too comfortable: 'Line Dancer' malware may be targeting other vendors, too

With Run:ai acquisition, Nvidia aims to manage your AI kubes

Now Jensen has a control plane to play with his army of NIMs

Apple releases OpenELM, a slightly more accurate LLM

It's not the fastest machine learning model, but you can't have everything