banner Expire 1 July 2024
Ad Ends 13 April 2024
banner Expire 15 July 2024
banner Expire 18 April 2024
ad End 18 October 2024
Ad Ends 13 July 2023
banner Expire 20 May 2024
What's new
Ad expire at 5 May 2024
UniCvv
CrdCrew.cc Carding forum
Western union transfer
banner expire at 21 August

Carding.pw carding forum
adv exp at 23 may

Cyberattacks hit millions of WordPress sites

Daniel

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
6,487
Reaction score
890
Points
212
Awards
2
  • trusted user
  • Rich User
Cybercriminals have discovered a zero-day vulnerability in the popular File Manager plugin.





Defiant has documented a spike in cyber attacks on WordPress sites last week . According to them, cybercriminals tried to attack millions of sites in search of a vulnerable File Manager plugin.

Attackers discovered a zero-day vulnerability in older versions of File Manager that could allow unauthorized files, including malicious ones, to be uploaded to a website. How the vulnerability was discovered is unknown, but last week cybercriminals began actively looking for this plugin on websites. Upon discovering the vulnerable File Manager, they exploited the vulnerability, gained access to the web shell, seized control of the site, and incorporated it into the botnet.

At first, the number of recorded attacks was small, but by September 4, their number had reached 1 million. In total, since September 1, when the attacks just began, Defiant specialists blocked attempts to attack 1.7 million WordPress sites - this is more than half of the sites protected using Defiant's Wordfence firewall. According to company analyst Ram Gall, the actual number of attacks could be much higher.

The File Manager developers released a fix for the vulnerability the same day the cyber attacks became known. Some site owners have installed it, however many sites are still running the affected version of the plugin.

Due to the slow installation of patches, the WordPress developers recently added a feature to automatically update plugins and themes to their content management system. So, starting with WordPress 5.5, released last month, site owners can turn on automatic updates, and plugins and themes will update themselves every time a patch is released.
 
Ad End 1 July 2024
Top