I vad som ser ut att vara en eskalerande attack så har ett mycket stort antal webbplatser attackerats och flera av dem har drabbats av intrång via buggar i olika plugins, skriver säkerhetsföretaget Wordfence. Attackerna riktar sig gamla säkerhetshål och mot webbplatser som slarvat med uppdateringarna.
Det visar sig att den senaste tidens inrapporterade attacker, kapade webbplatser och buggar i en del plugins hänger samman i en mer samordnad, större attack.
- An XSS vulnerability in the Easy2Map plugin, which was removed from the WordPress plugin repository in August of 2019, and which we estimate is likely installed on less than 3,000 sites. This accounted for more than half of all of the attacks.
- An XSS vulnerability in Blog Designer which was patched in 2019. We estimate that no more than 1,000 vulnerable installations remain, though this vulnerability was the target of previous campaigns.
- An options update vulnerability in WP GDPR Compliance patched in late 2018 which would allow attackers to change the site’s home URL in addition to other options. Although this plugin has more than 100,000 installations, we estimate that no more than 5,000 vulnerable installations remain.
- An options update vulnerability in Total Donations which would allow attackers to change the site’s home URL. This plugin was removed permanently from the Envato Marketplace in early 2019, and we estimate that less than 1,000 total installations remain.
- An XSS vulnerability in the Newspaper theme which was patched in 2016. This vulnerability has also been targeted in the past.
Plugins
De flesta intrången har möjliggjorts via plugins med säkerhetshål som åtgärdats för länge sedan. En del buggar är flera år gamla men trots det så har de drabbade webbplatserna inte uppdaterat sina plugins och tillägg.
In today’s post we covered a large-scale attack against nearly a million individual sites, including the functionality of the attack payload. All Wordfence users, including sites running the free version of Wordfence as well as Wordfence Premium, are protected against these attacks. Nonetheless, we urge site owners to ensure that all of their plugins are up to date and to deactivate and delete any plugins that have been removed from the WordPress plugin repository.


0 kommentarer