{"id":812,"date":"2024-07-01T07:20:51","date_gmt":"2024-07-01T07:20:51","guid":{"rendered":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/07\/01\/researchers-uncover-active-exploitation-of-wordpress-plugin-vulnerabilities-the-hacker-news\/"},"modified":"2024-07-01T07:20:51","modified_gmt":"2024-07-01T07:20:51","slug":"researchers-uncover-active-exploitation-of-wordpress-plugin-vulnerabilities-the-hacker-news","status":"publish","type":"post","link":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/07\/01\/researchers-uncover-active-exploitation-of-wordpress-plugin-vulnerabilities-the-hacker-news\/","title":{"rendered":"Researchers Uncover Active Exploitation of WordPress Plugin Vulnerabilities &#8211; The Hacker News"},"content":{"rendered":"<p>Cybersecurity researchers have warned that multiple high-severity security vulnerabilities in WordPress plugins are being actively exploited by threat actors to create rogue administrator accounts for follow-on exploitation.<br \/>&#8220;These vulnerabilities are found in various WordPress plugins and are prone to unauthenticated stored cross-site scripting (XSS) attacks due to inadequate input sanitization and output escaping, making it possible for attackers to inject malicious scripts,&#8221; Fastly researchers Simran Khalsa, Xavier Stevens, and Matthew Mathur <a href=\"https:\/\/www.fastly.com\/blog\/active-exploitation-unauthenticated-stored-xss-vulnerabilities-wordpress\/\" rel=\"noopener\" target=\"_blank\">said<\/a>.<br \/>The security flaws in question are listed below &#8211;<br \/>Attack chains exploiting the flaws involve injecting a payload that points to an obfuscated JavaScript file hosted on an external domain, which is responsible for creating a new admin account, inserting a backdoor, and setting up tracking scripts.<br \/>The PHP backdoors are injected into both plugin and theme files, while the tracking script is designed to send an HTTP GET request containing the HTTP host information to a remote server (&#8220;ur.mystiqueapi[.]com\/?ur&#8221;).<br \/>Fastly said it detected a significant proportion of the exploitation attempts originating from IP addresses associated with the Autonomous System (AS) IP Volume Inc. (<a href=\"https:\/\/ipinfo.io\/AS202425\" rel=\"noopener\" target=\"_blank\">AS202425<\/a>), with a chunk of it coming from the Netherlands.<br \/>It&#8217;s worth noting that WordPress security company WPScan <a href=\"https:\/\/thehackernews.com\/2024\/05\/hackers-exploiting-litespeed-cache-bug.html\" rel=\"noopener\" target=\"_blank\">previously disclosed<\/a> similar attack efforts targeting CVE-2023-40000 to create rogue admin accounts on susceptible websites.<br \/>To mitigate the risks posed by such attacks, it&#8217;s recommended that WordPress site owners review their installed plugins, apply the latest updates, and audit the sites for signs of malware or the presence of suspicious administrator users.<br \/>Continuous Attack Surface Discovery &#038; Penetration Testing<br \/>Continuously discover, prioritize, &#038; mitigate exposures with evidence-backed ASM, Pentesting, and Red Teaming.<br \/>Facing identity threats? Discover how ITDR can save you from lateral movement and ransomware attacks.<br \/>From data breaches to identity theft, compromised credentials can cost you everything. Learn how to stop attackers in their tracks.<br \/>Get the latest news, expert insights, exclusive resources, and strategies from industry leaders &#8211; all for free.<\/p>\n<p><a href=\"https:\/\/news.google.com\/rss\/articles\/CBMiTmh0dHBzOi8vdGhlaGFja2VybmV3cy5jb20vMjAyNC8wNS9yZXNlYXJjaGVycy11bmNvdmVyLWFjdGl2ZS1leHBsb2l0YXRpb24uaHRtbNIBAA?oc=5\">source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have warned that multiple high-severity security vulnerabilities in WordPress plugins are being actively exploited by threat actors to create rogue administrator accounts for follow-on exploitation.&#8220;These vulnerabilities are found in various WordPress plugins and are prone to unauthenticated stored cross-site scripting (XSS) attacks due to inadequate input sanitization and&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-812","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/comments?post=812"}],"version-history":[{"count":0,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/812\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/media?parent=812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/categories?post=812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/tags?post=812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}