Hackers often target WordPress plugins as they have security loopholes that they can exploit to hack into sites without permission.
Once they have found them, threat actors can insert corrupted scripts into these loopholes to compromise the system, obtain secret data, and carry out any other attack that serves their requirements.
Cybersecurity researchers at WPScan recently discovered that hackers have been actively exploiting the WP Automatic updates plugin vulnerability, tracked as “CVE-2024-27956.”
This critical flaw in the WP-Automatic plugin allows threat actors to bypass authentication, create admin accounts, upload malicious files, and potentially compromise affected websites through a SQL injection vulnerability that was discovered a few weeks ago.
The problem is due to incorrect user authentication handling, which permits the injection of harmful SQL queries.
Is Your Network Under Attack? - Read CISO’s Guide to Avoiding the Next Breach - Download Free Guide
On 13 March, PatchStack released it publicly and recorded over 5.5 million attempts at attack, which peaked on 31 March after gradually increasing. This security hole is very dangerous as it can result in a complete site takeover.
Attackers exploit the SQL Injection (SQLi) vulnerability by injecting malicious SQL queries that create admin accounts, upload web shells and backdoors, and rename the plugin file being exploited for continuous use.
Afterward, they install plugins that allow more code editing and file uploads while hiding their tracks.
Owners, security tools, and other threat actors can be blocked and remain undetected by renaming the plugin file.
Persistence is achieved through full control as threat actors apply backdoors to control them using different malicious plugins or themes.
Here below, we have mentioned all the mitigations recommended by the cybersecurity analysts:-
Combat Email Threats with Easy-to-Launch Phishing Simulations: Email Security Awareness Training -> Try Free Demo
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…