x

WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

(Cyberscoop)

A new vulnerability in a popular WordPress plugin could allow outsiders who exploit the flaw to take control of a website, according to new research.

Luka Šikić, who works as a security developer at WebARX, published a report Monday revealing the bug in the Simple Social Buttons plugin, which more than 40,000 websites use to distribute their content on Facebook, Twitter and others. The problem would allow hackers to modify a WordPress site’s settings in a way plugin developers did not intend.

WPBrigade, the firm that developed Simple Social Buttons, patched the flaw in the 2.0.22 software update, which was released Friday. Šikić said he informed WPBrigade about the vulnerability on Feb. 7, and that the company fixed the issue within a day.

“If your website uses the WordPress plugin ‘Simple Social Buttons,’ you should update it to the latest version as soon as possible,” WebARX said in a blog post detailing the findings.

WebARX’s research comes just weeks after an unrelated incident in which a former employee hacked the website of WPML, another popular WordPress plugin that allows WordPress operators to run their websites in different language. In that case, WPML said the former employee used inside information and a hidden vulnerability to send spam to WPML clients.

In another case last year, hackers exploited a bug in the plugin WP GDPR Compliance to create their own administrator accounts on WordPress websites.

The sheer popularity of the WordPress content management system makes websites hosted there an alluring hacking target. Of the roughly 182 million websites active online, according to the internet research company Netcraft, some 60 million of those are WordPress, W3Techs data says. By infiltrating one component of the WordPress environment, attackers could leverage that vulnerability into many others.

Hot this week

Eid-el-Fitr: Kogi Governor Ododo Urges Unity, Prayers for Nigeria

Kogi State Governor Ahmed Usman Ododo has extended Eid-el-Fitr...

Ozoro Festival: Delta CP wades in, reaffirms commitment to justice

By Anne AzukaDelta State Commissioner of Police, Aina...

Media Rights Group Condemns Alleged Assault on Journalist by Police in Bauchi

Media Rights Agenda (MRA) has condemned the reported assault...

DWI defends Ribadu, faults Ishola Williams’ call for security overhaul

Democracy Watch Initiative, DWI, has strongly criticised recent remarks...

Nigeria, China Mark First International Taijiquan Day in Abuja

Nigeria and China have reinforced their expanding cooperation in...

Wike Warns Makinde, Don’t Ignite a Fight You Cannot Finish

By Joyce Remi - BabayejuThe FCT Minister, Barr. Nyesom...

SGF Inaugurates PenCom Board, Emphasises Transparency and Accountability

By Wilfred FrancisThe Secretary to the Government of...

EFCC Arraigns Man Over Alleged ₦9.87m Theft in Lagos Court

By Francis WilfredThe Economic and Financial Crimes Commission...

EFCC Investigates Man Over Alleged ₦19.9m Visa Fraud in Enugu

By Wilfred FrancisThe Economic and Financial Crimes Commission...

APC Leaders Urge Unity, Grassroots Mobilisation at South-South Summit in Asaba

Governors Hope Uzodimma of Imo State and Sheriff Oborevwori...

ADC Stakeholders Back Mohammed Abdullahi for Nasarawa Governorship, Urge Unity Ahead of 2027

Stakeholders of the African Democratic Congress (ADC) in Nasarawa...

Media Rights Group Condemns Alleged Assault on Journalist by Police in Bauchi

Media Rights Agenda (MRA) has condemned the reported assault...

Related Articles

Popular Categories

spot_imgspot_img