x

WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

(Cyberscoop)

A new vulnerability in a popular WordPress plugin could allow outsiders who exploit the flaw to take control of a website, according to new research.

Luka Šikić, who works as a security developer at WebARX, published a report Monday revealing the bug in the Simple Social Buttons plugin, which more than 40,000 websites use to distribute their content on Facebook, Twitter and others. The problem would allow hackers to modify a WordPress site’s settings in a way plugin developers did not intend.

WPBrigade, the firm that developed Simple Social Buttons, patched the flaw in the 2.0.22 software update, which was released Friday. Šikić said he informed WPBrigade about the vulnerability on Feb. 7, and that the company fixed the issue within a day.

“If your website uses the WordPress plugin ‘Simple Social Buttons,’ you should update it to the latest version as soon as possible,” WebARX said in a blog post detailing the findings.

WebARX’s research comes just weeks after an unrelated incident in which a former employee hacked the website of WPML, another popular WordPress plugin that allows WordPress operators to run their websites in different language. In that case, WPML said the former employee used inside information and a hidden vulnerability to send spam to WPML clients.

In another case last year, hackers exploited a bug in the plugin WP GDPR Compliance to create their own administrator accounts on WordPress websites.

The sheer popularity of the WordPress content management system makes websites hosted there an alluring hacking target. Of the roughly 182 million websites active online, according to the internet research company Netcraft, some 60 million of those are WordPress, W3Techs data says. By infiltrating one component of the WordPress environment, attackers could leverage that vulnerability into many others.

Hot this week

Editors Urge Government To Create Safe, Enabling Environment For Journalists

· Ask security agents to find missing Vanguard journalistAs...

EXCLUSIVE: Buhari orders probe of Isa Funtua, AMCON over keystone and Etisalat

Following the controversy generated by the leading opposition party,...

6 Signs your boyfriend thinks you are ugly -Take note of No. 2

They say there are three kinds of people; the...

2023: South-East, Middle Belt Forum Endorses Peter Obi

The South-East and Middle Belt Forum has endorsed the...

Wike: PDP Can’t Win 2027, Party Being Undermined by Self-Interest

Federal Capital Territory (FCT) Minister Nyesom Wike has declared...

Sex-for-Grade: Over 50 Nigerian Lecturers Sanctioned for Sexual Misconduct in Four Years

At least 50 lecturers across public universities and polytechnics...

Fubara’s Visit to Wike a Sacrifice for Peace – Rivers Elders

The Rivers Elders Council and pioneer spokesperson of the...

Court Orders EFCC to Return $20,000 Bail Condition to Owner

An Ikeja Special Offences Court has ordered the Economic...

Cultural Exchange: CGC Hosts Chinese Art Performance in Abuja

CGC Nigeria Limited on Monday hosted a Chinese Pingtan...

St. Augustine College Student, Anthony Toruka Scores 364 out of 400 in 2025 UTME Results

By Joyce Remi-BabayejuA Sixteen-year-old Anthony Chinecherem Toruka, a student...

Apreala Urges Bayelsa Queens to Finish Strong in NWFL Super Six

Amgbare Ekaunkumo, YenagoaChairman Pastor Robin Angonimi Apreala is rallying...
spot_img

Related Articles

Popular Categories

spot_imgspot_img