Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

This WordPress plugin with 5 million users could have a serious security flaw

  • August 31, 2023
Total
0
Shares
0
0
0


Cybersecurity researchers from Patchstack recently discovered a high-severity flaw in a popular extension for WordPress, which allows threat actors to exfiltrate sensitive information from vulnerable websites.

The vulnerability is tracked as CVE-2023-40004, and is described as allowing unauthenticated users to access and tweak token configurations. The flaw was found in an extension called All-in-One WP Migration, which has five million active installations. 

This is an add-on that allows non-technical WP admins to quickly and seamlessly migrate their WP data from one place to another. That being said, the flaw could be abused to redirect website migration data to threat actors’ own servers, or to restore malicious backups.

Multiple vulnerable add-ons

The flaw was discovered in mid-July this year and was subsequently reported to the plugin’s creators, ServMask. The company released an update roughly a week later, addressing the issue with permission and nonce validation to the init function. 

The silver lining, according to BleepingComputer, is that the extension is only used during migration and should not be active (and thus, a threat) at any other time. 

The bad news is that the researchers found the same piece of vulnerable code in a few other extensions from the same manufacturer, including the Box extension, Google Drive extension, One Drive extension, and Dropbox extension.

To secure their websites, WP admins are advised to make sure their extensions are upgraded to these versions:

Box Extension: v1.54
Google Drive Extension: v2.80
OneDrive Extension: v1.67
Dropbox Extension: v3.76

All-in-One WP Migration should be upgraded to v7.78.

WordPress is by far the world’s most popular content management system (CMS), with roughly half of all internet websites powered by the product. As such, it’s a popular target among cybercriminals. 

While WordPress itself is generally considered safe, it’s the add-ons (mostly the free ones) that are usually the weakest link in the cybersecurity chain. 

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

VanMoof, Trendy E-Bike Brand, Bought Out of Bankruptcy by Scooter Maker

  • August 31, 2023
View Post
Next Article
  • Technology

In a surprise tie-up, Shopify merchants will be able to offer Amazon’s ‘Buy with Prime’ option

  • August 31, 2023
View Post
You May Also Like
View Post
  • News

Taiwan has cutting-edge display tech to show off with Taiwan Excellence Awards

  • October 4, 2023
View Post
  • News

Quordle today – hints and answers for Thursday, October 5 (game #619)

  • October 4, 2023
View Post
  • News

This YouTube video shows tiny Intel rival running x86 code in emulation — weeks after announcing 192-core monster CPU

  • October 4, 2023
View Post
  • News

‘Mean Girls’ Has a One-Day Run on TikTok

  • October 4, 2023
View Post
  • News

“Mean Girls” Has a One-Day Run on TikTok

  • October 4, 2023
View Post
  • News

Pixel 8 Pro houses its own generative AI model – here’s what it means

  • October 4, 2023
View Post
  • News

Microsoft C.E.O. Testifies That Google’s Power in Search Is Ubiquitous

  • October 4, 2023
View Post
  • News

Google Pixel 8 and Google Photos: the 7 biggest new camera tricks

  • October 4, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.