Hackers exploit patched WordPress bugs, risking millions of sites
Hackers are actively exploiting two recently patched security vulnerabilities in WordPress, putting millions of websites at risk of remote takeover. The flaws, which were disclosed and fixed in late October, allow attackers to gain full control of a site without needing a password. According to cybersecurity researcher Marc Montpas of Sucuri, the vulnerabilities affect all versions of WordPress prior to the latest update, potentially impacting tens of millions of websites that run the popular content management system.
The two bugs are a stored cross-site scripting (XSS) vulnerability and a remote code execution (RCE) flaw. The XSS flaw could let an attacker inject malicious scripts into a site, while the RCE flaw could allow them to execute arbitrary code on the server. Combined, these could lead to complete site compromise, including data theft, malware distribution, and defacement. Montpas estimates that the number of vulnerable sites is in the tens of millions, given WordPress powers over 40% of all websites.
WordPress released security updates on October 30, 2024, to address these issues. However, many site owners have not yet applied the patches, leaving their sites exposed. The researcher warned that exploit code is already circulating, and attacks have been observed in the wild. He urged all WordPress administrators to update their installations immediately to version 6.6.3 or later, and to check for any signs of compromise.
This is not the first time WordPress has faced widespread exploitation of security flaws. In the past, similar vulnerabilities have led to large-scale botnets and website takeovers. The current situation underscores the importance of timely updates, especially for sites handling sensitive data or running e-commerce operations. Going forward, site owners should enable automatic updates and consider additional security measures such as web application firewalls and regular security audits to mitigate risks.
Sources
- TechCrunchSecondary
Related
Cyera acquires Oasis Security for $1B in third deal this year
ChatGPT hack overwhelms tech firm, emergency call held
Microsoft unveils AI security tools it says outperform competing platforms
Private Claude chats exposed in Google and Bing search results
Apple sued after alleged App Store crypto scam cost users $1.8M
Microsoft unveils cybersecurity AI tools
Claude AI shared chats indexed by Google before removal
Hugging Face CEO urges transparency after 'unprecedented' OpenAI hack
Trending now
- Audi unveils 2027 Q9 full-size SUV flagship for US
- Mexican cartels outsource meth labs to Nigeria
- Kenya probes 15 elephant deaths in Amboseli park
- Meta's AI data center financing costs rise in $14 billion BlackRock deal
- Cyera acquires Oasis Security for $1B in third deal this year
- NASA Swift rescue mission hits attitude control trouble
- American Airlines grounds all flights nationwide after IT outage
- SK Hynix Q2 profit surges 557% to record high
Comments
No comments yet. Be the first.