x

WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

(Cyberscoop)

A new vulnerability in a popular WordPress plugin could allow outsiders who exploit the flaw to take control of a website, according to new research.

Luka Šikić, who works as a security developer at WebARX, published a report Monday revealing the bug in the Simple Social Buttons plugin, which more than 40,000 websites use to distribute their content on Facebook, Twitter and others. The problem would allow hackers to modify a WordPress site’s settings in a way plugin developers did not intend.

WPBrigade, the firm that developed Simple Social Buttons, patched the flaw in the 2.0.22 software update, which was released Friday. Šikić said he informed WPBrigade about the vulnerability on Feb. 7, and that the company fixed the issue within a day.

“If your website uses the WordPress plugin ‘Simple Social Buttons,’ you should update it to the latest version as soon as possible,” WebARX said in a blog post detailing the findings.

WebARX’s research comes just weeks after an unrelated incident in which a former employee hacked the website of WPML, another popular WordPress plugin that allows WordPress operators to run their websites in different language. In that case, WPML said the former employee used inside information and a hidden vulnerability to send spam to WPML clients.

In another case last year, hackers exploited a bug in the plugin WP GDPR Compliance to create their own administrator accounts on WordPress websites.

The sheer popularity of the WordPress content management system makes websites hosted there an alluring hacking target. Of the roughly 182 million websites active online, according to the internet research company Netcraft, some 60 million of those are WordPress, W3Techs data says. By infiltrating one component of the WordPress environment, attackers could leverage that vulnerability into many others.

Hot this week

Uyo Tropicana Trade Fair to catalize investment and economic expansion- Ekong

By Ogenyi Ogenyi. UyoThe Akwa Ibom Commissioner for Trade...

Innovation Support Network Elects New Board at 6th Annual General Gathering in Kano

By Jabiru HassanThe Innovation Support Network (ISN), Nigeria’s leading...

English Premier League Table

Season 2025–26RankClubMPMatches playedWWinsDDrawsLLossesPtsPointsGFGoals scoredGAGoals againstGDGoal differenceLast 5Last 5 matchesUEFA Champions...

Wike Frowns at Performance of Abuja Waste Management Contractors

… Calls for a Cĺean FCTBy Joyce Remi-BabayejuThe FCT...

‘Single Mother Stigma Only Applies to Poor Women’ – Mercy Eke

Nigerian reality TV star and Big Brother Naija Season...

Pius Akutah’s Alleged Fraud at Nigerian Shippers Council Uncovered

Investigations by Nigerian Concord Newspaper reveal that the Executive...

Uyo Tropicana Trade Fair to catalize investment and economic expansion- Ekong

By Ogenyi Ogenyi. UyoThe Akwa Ibom Commissioner for Trade...

FG’s CNG Drive Best for Nigeria’s Sustainable Transport System —Mahmoud Hints

By Joyce Remi-BabayejuFCT Minister of State, Dr. Mariya Mahmoud,...

Delta Government Reaffirms Strong Partnership with Media to Advance MORE Agenda

By Anne AzukaThe Delta State Government has reaffirmed its...

Plateau Government Completes Preparations for 2025 Unity Christmas Carols and Praise Festival

By Israel Adamu, JosThe Plateau State Government has finalized...

Kogi Police Debunk Rumoured Bandit Invasion of Lokoja Communities

By Noah Ocheni, LokojaThe Kogi State Police Command has...

Troops Arrest Air Force Personnel in Kogi for Alleged Arms Trafficking

By Noah Ocheni, LokojaTroops of the 12 Brigade,...

Kidnapped Anglican Priest Edwin Achie Killed After Audio Plea for ₦600m Ransom

By Achadu Gabriel, KadunaAn Anglican Church priest, Rev. Edwin...

Related Articles

Popular Categories

spot_imgspot_img