Cybersecurity

Hackers exploit patched WordPress bugs, risking millions of sites

1 min read

0 0
XWhatsAppTelegramLinkedIn

Hackers are actively exploiting two recently patched security vulnerabilities in WordPress, putting millions of websites at risk of remote takeover. The flaws, which were disclosed and fixed in late October, allow attackers to gain full control of a site without needing a password. According to cybersecurity researcher Marc Montpas of Sucuri, the vulnerabilities affect all versions of WordPress prior to the latest update, potentially impacting tens of millions of websites that run the popular content management system.

The two bugs are a stored cross-site scripting (XSS) vulnerability and a remote code execution (RCE) flaw. The XSS flaw could let an attacker inject malicious scripts into a site, while the RCE flaw could allow them to execute arbitrary code on the server. Combined, these could lead to complete site compromise, including data theft, malware distribution, and defacement. Montpas estimates that the number of vulnerable sites is in the tens of millions, given WordPress powers over 40% of all websites.

WordPress released security updates on October 30, 2024, to address these issues. However, many site owners have not yet applied the patches, leaving their sites exposed. The researcher warned that exploit code is already circulating, and attacks have been observed in the wild. He urged all WordPress administrators to update their installations immediately to version 6.6.3 or later, and to check for any signs of compromise.

This is not the first time WordPress has faced widespread exploitation of security flaws. In the past, similar vulnerabilities have led to large-scale botnets and website takeovers. The current situation underscores the importance of timely updates, especially for sites handling sensitive data or running e-commerce operations. Going forward, site owners should enable automatic updates and consider additional security measures such as web application firewalls and regular security audits to mitigate risks.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.