Sunday, May 28, 2023
Aroged
  • Home
  • Games
  • Technology
  • Sports
No Result
View All Result
  • Home
  • Games
  • Technology
  • Sports
No Result
View All Result
Aroged
No Result
View All Result
Home Games

Vulnerability actively exploited by hackers discovered in one of the most popular plugins for WordPress

Hazel Vasquez by Hazel Vasquez
April 1, 2023
in Games
Vulnerability actively exploited by hackers discovered in one of the most popular plugins for WordPress
0
SHARES
12
VIEWS
Share on FacebookShare on Twitter

Hackers began to actively exploit a vulnerability found in the paid Elementor Pro plugin for CMS WordPress, the world’s most popular website creation platform. The plugin is installed on 12 million WordPress sites, and the vulnerability is rated 8.8 out of 10, which means it has the status of critical.

  Image source: Gerd Altmann / pixabay.com

Image source: Gerd Altmann / pixabay.com

Elementor Pro offers tools to simplify the development and management of site elements, and also includes tools for interacting with the WooCommerce plugin for creating online stores. The vulnerability manifests itself on sites with both Elementor Pro and WooCommerce installed: any registered user can create new accounts with administrator privileges. Last week, the Elementor Pro developer released version 3.11.7 update, in which the vulnerability was closed.

The vulnerability is related to the Elementor Pro and WooCommerce interaction module – one of its functions is designed to update some parameters of the online store, but data entry is not validated, and the function itself does not have the means to restrict access to users with insufficient privileges. As a result, an attacker who has gained administrator rights, in particular, can change the siteurl parameter in order to redirect all traffic from an infected site to an external malicious resource. Attacks on sites with an outdated version of the plugin are often carried out from IP addresses 193.169.194.63, 193.169.195.64 and 194.135.30.6; and files named wp-resortpack.zip, wp-rate.php, and lll.zip often appear on a hacked site.

If you notice an error, select it with the mouse and press CTRL + ENTER.

Tags: activelydiscoveredexploitedHackerspluginspopularvulnerabilityWordPress

Related Posts

ViewSonic VX2479-2K-PRO monitor is priced at $140
Games

ViewSonic VX2479-2K-PRO monitor is priced at $140

by Aroged
May 28, 2023
Adventure detective game Marlon’s Mystery: The Darkside of Crime is out for PC and Nintendo Switch
Games

Adventure detective game Marlon’s Mystery: The Darkside of Crime is out for PC and Nintendo Switch

by Aroged
May 28, 2023
NVIDIA capitalization increased by $ 198 billion in a day – this is more than the entire cost of Intel or AMD
Games

NVIDIA capitalization increased by $ 198 billion in a day – this is more than the entire cost of Intel or AMD

by Hazel Vasquez
May 28, 2023
Streaming platform Kick already has a category for Grand Theft Auto 6
Games

Streaming platform Kick already has a category for Grand Theft Auto 6

by Aroged
May 28, 2023
Mass Effect fans believe there is “no reason” for one of the companions not to return to ME4
Games

Mass Effect fans believe there is “no reason” for one of the companions not to return to ME4

by Aroged
May 27, 2023
Next Post
Test winner: The best fully automatic coffee machine at Stiftung Warentest

Test winner: The best fully automatic coffee machine according to Stiftung Warentest

EK Water Blocks: EK-Nucleus AiO coolers deliberately do without flashy RGB lighting

EK Water Blocks: EK-Nucleus AiO coolers deliberately do without flashy RGB lighting

PlayStation Showcase: The big event on PS5 will be before the Summer Game Fest, for Grubb

PlayStation Showcase: The big event on PS5 will be before the Summer Game Fest, for Grubb

Brandon Sanderson recognizes that there is something in video games much better than in books

Brandon Sanderson recognizes that there is something in video games much better than in books

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

OLED TV promo: the LG C2 65 inches at -30% will not last long at this price

OLED TV promo: the LG C2 65 inches at -30% will not last long at this price

March 22, 2023
Fake baby bump: smuggler is "pregnant" with iPhones and CPUs

Fake baby bump: smuggler is “pregnant” with iPhones and CPUs

December 3, 2022
GTA 5 became the most downloaded PS5 game on the PlayStation Store in January 2023

GTA 5 became the most downloaded PS5 game on the PlayStation Store in January 2023

February 11, 2023

Browse by Category

  • Games
  • Sports
  • Technology
  • Uncategorized

Browse by Tags

action Amazon AMD Announced Apple Aroged Coming date Final Football Free Game gameplay games Google Hogwarts Legacy LIVE Match Microsoft news Nintendo NVIDIA online Pass PlayStation Price Pro PS5 release released Remake Samsung Season Series star Steam Switch trailer Update video war Watch World Xbox
Aroged

News Around World And News About Business, Entertainment, Fashion, Food, Games News, Health, PC Portables, Telecomtalk, Sports, Make Money Online and more all on one platform.

Categories

  • Games
  • Sports
  • Technology
  • Uncategorized

Browse by Tag

action Amazon AMD Announced Apple Aroged Coming date Final Football Free Game gameplay games Google Hogwarts Legacy LIVE Match Microsoft news Nintendo NVIDIA online Pass PlayStation Price Pro PS5 release released Remake Samsung Season Series star Steam Switch trailer Update video war Watch World Xbox

Recent Posts

  • ViewSonic VX2479-2K-PRO monitor is priced at $140
  • Marta Kostyuk – Arina Sobolenko. Watch online. LIVE broadcast
  • Adventure detective game Marlon’s Mystery: The Darkside of Crime is out for PC and Nintendo Switch
  • About Us
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Games
  • Technology
  • Sports

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.