Vietnam.vn - Nền tảng quảng bá Việt Nam

Websites using WordPress need to delete these 2 plugins

Báo Thanh niênBáo Thanh niên21/03/2024


According to The Hacker New , two WordPress plugins, Malware Scanner and Web Application Firewall by miniOrage, are vulnerable to a serious security flaw, CVE-2024-2172, discovered by Stiofan, with a severity score of 9.8 on a 10-point scale of the CVSS security vulnerability scoring system.

The bug has a wide impact because even though the developer removed it from the WordPress app store on March 7, 2024, it can still have an impact because Malware Scanner has been recorded as being installed and active on up to 10,000 websites, while with Web Application Firewall it is 300.

Wordfence said the vulnerability was the result of a missing check in the plugin's code, allowing an unauthenticated attacker to arbitrarily update any user's password and escalate privileges to administrator, potentially leading to a complete compromise of the website.

Các website dùng WordPress cần xóa 2 plugin này- Ảnh 1.

As the most popular CMS platform, WordPress is a target for hackers.

With administrative rights, hackers can easily download additional plugins, malicious zip files containing backdoors, and modify website posts to redirect users to other malicious websites.

Previously, a similar plugin, RegistrationMagic, was reported with the bug code CVE-2024-1991 and CVSS score 8.8, which is also a high severity privilege escalation vulnerability. This plugin has also been downloaded and installed more than 10,000 times.

WordPress is a famous open source content management system (CMS), widely used in the world . The ease of installation, posting and managing content on this CMS platform makes WordPress an ideal platform for all types of websites such as online stores, portals, discussion forums... According to w3techs , this CMS platform is currently chosen by 43.1% of websites in the world.



Source link

Comment (0)

No data
No data
Admire the million-year-old Chu Dang Ya volcano in Gia Lai
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony

Heritage

Figure

Business

No videos available

News

Political System

Local

Product