Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Up to 1.5 million WordPress sites could be hit by this security flaw – so patch up now

  • May 25, 2023
Total
0
Shares
0
0
0


Hackers are reportedly using an Unauthenticated Stored Cross-Site Scripting (XSS) flaw in a WordPress plugin to target thousands of websites, experts have warned.

Cybersecurity researchers from Defiant discovered the flaw in Beautiful Cookie Consent Banner, a WP cookie consent plugin with more than 40,000 active installations. The attackers could use the vulnerability to add malicious JavaScripts into the compromised websites, which would then be executed in the visitors’ browsers. 

Cybercriminals can use XSS for a number of things, from stealing sensitive data and sessions, to complete takeover of the vulnerable website. In this particular case, threat actors can create admin accounts, which is enough privilege to completely take over the website. 

Millions of affected sites

Beautiful Cookie’s creators recently released a patch for the flaw, so if you’re using the plugin, make sure it’s updated to version 2.10.2.

“According to our records, the vulnerability has been actively attacked since February 5, 2023, but this is the largest attack against it that we have seen,” Defiant’s Ram Gall said. “We have blocked nearly 3 million attacks against more than 1.5 million sites, from nearly 14,000 IP addresses since May 23, 2023, and attacks are ongoing.”

The silver lining in the news is that the attackers’ exploit seems to be misconfigured in a way that it’s unlikely to deploy a payload, even if it targets a website running an old and vulnerable version of the plugin. Still, the researchers urge webmasters and owners to apply the patch, as even a failed attempt can corrupt the plugin’s configuration. 

The patch sorts this problem out as well, as the plugin is capable of repairing itself. 

What’s more, as soon as the hacker realizes their mistake, they can quickly address it and potentially infect the sites that haven’t been patched yet.

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Sam Altman’s crypto project Worldcoin got more coin in latest $115M raise

  • May 25, 2023
View Post
Next Article
  • Technology

When new grant program, OpenAI aims to crowdsource AI regulation

  • May 25, 2023
View Post
You May Also Like
View Post
  • News

WWDC 2023: the 3 big reveals we need from Apple

  • June 4, 2023
View Post
  • News

GTA 5 took 10 years to introduce this feature and we’re so pleased it’s finally here

  • June 4, 2023
View Post
  • News

This new Steam update will show you the lowest price a game has sold for in the last 30 days

  • June 4, 2023
View Post
  • News

This Google Workspace security flaw could let hackers quietly steal your Drive files

  • June 4, 2023
View Post
  • News

Apple rumored to be announcing major Siri updates at WWDC 2023

  • June 4, 2023
View Post
  • News

These Activists Distrust Voting Machines. Just Don’t Call Them Election Deniers.

  • June 4, 2023
View Post
  • News

Quordle today – hints and answers for Sunday, June 4 (game #496)

  • June 4, 2023
View Post
  • News

Diablo 4’s authentication servers are down, preventing players from logging in

  • June 3, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.