x

WordPress plugin patches flaw that gave hackers potential access to 40,000 websites

(Cyberscoop)

A new vulnerability in a popular WordPress plugin could allow outsiders who exploit the flaw to take control of a website, according to new research.

Luka Šikić, who works as a security developer at WebARX, published a report Monday revealing the bug in the Simple Social Buttons plugin, which more than 40,000 websites use to distribute their content on Facebook, Twitter and others. The problem would allow hackers to modify a WordPress site’s settings in a way plugin developers did not intend.

WPBrigade, the firm that developed Simple Social Buttons, patched the flaw in the 2.0.22 software update, which was released Friday. Šikić said he informed WPBrigade about the vulnerability on Feb. 7, and that the company fixed the issue within a day.

“If your website uses the WordPress plugin ‘Simple Social Buttons,’ you should update it to the latest version as soon as possible,” WebARX said in a blog post detailing the findings.

WebARX’s research comes just weeks after an unrelated incident in which a former employee hacked the website of WPML, another popular WordPress plugin that allows WordPress operators to run their websites in different language. In that case, WPML said the former employee used inside information and a hidden vulnerability to send spam to WPML clients.

In another case last year, hackers exploited a bug in the plugin WP GDPR Compliance to create their own administrator accounts on WordPress websites.

The sheer popularity of the WordPress content management system makes websites hosted there an alluring hacking target. Of the roughly 182 million websites active online, according to the internet research company Netcraft, some 60 million of those are WordPress, W3Techs data says. By infiltrating one component of the WordPress environment, attackers could leverage that vulnerability into many others.

Hot this week

Governor Sule and the Two Horsemen: How Synergy Is Redefining Governance in Nasarawa

By Leo Zwanke, Lafia When Engineer Abdullahi Sule assumed office...

China Inaugurates 14th ‘Chinese Corner’ in Abuja

By Francis Wilfred The Chinese Embassy in Nigeria has inaugurated...

8th Zenith Bank/Delta Principals’ Cup Kicks Off September 18

By Anne Azuka The 8th edition of the Zenith Bank/Delta...

Delta Govt Says Brazil Visit to Unlock Industrial Growth, Job Creation

By Anne Azuka The Delta State Government says its recent...

2 killed, 4 injured as DICON expired ordinance explodes in Kaduna

By Achadu Gabriel, kaduna An explosion which occurred Saturday at...

Fmr Nigeria’s SGF Gidado Idris’ family in disputes over Inheritance

…Stepmother allegedly barred siblings from property, ignore court orders…Children...

I Have Approved Demands of Resident Doctors – Wike

…Commends Them for Calling Off Strike By Joyce Remi-Babayeju Federal Capital...

FCT Health Secretary Declares, No Case of Ebola,Marburg in FCT

…Affirms Increased Surveillance in Abuja By Joyce Remi-Babayeju Contrary to recent...

Hajj 2025 Award: Mahmoud Reinstates Commitment to Hajj Exercise

By Joyce Remi-Babayeju The Federal Capital Territory Minister of State,...

A’ibom moves to end epileptic electricity at Summit

By Ogenyi Ogenyi,,Uyo In a renewed move to end electricity...

WIELD-I to Protest Against NAFDAC Over Toxic Chemicals, Fake Drugs

…Calls for Removal of Prof. Mojisola Christianah Adeyeye The Women’s...

Calls for Reform Dominate Global Governance Initiative Seminar in Abuja

Nigerian and Chinese officials, scholars, and policymakers have called...

Related Articles

Popular Categories

spot_imgspot_img