Thursday, 23 January 2025
25 C
Singapore
20.9 C
Thailand
20.9 C
Indonesia
25.7 C
Philippines

Over a million WordPress sites attacked by a hacker in a month

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher.  The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over […]

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher. 

The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over 500,000 individual sites, according to Ram Gall from Wordfence.

Over the past month, Wordfence, a security vendor, detected attacks on over 900,000 sites from more than 24,000 IP addresses, all of which appear to be from the same malicious hacker. That is because the attacker is attempting to inject a similar JavaScript payload to insert a backdoor into a victim website and redirect visitors.

The attacks seek to exploit a few cross-site scripting vulnerabilities in the Newspaper theme, Easy2Map plug-in, and the Blog Designer plug-in. It also targeted the WP GDPR Compliance plug-in as well as the Total Donations plug-in.

Gall warned that the hacker behind all this might be able to pivot other vulnerabilities in the future.

The JavaScript used to attack the sites is designed to redirect users who are not logged-in to a malvertising URL. If the users are logged-in, the JavaScript tries to inject a malicious backdoor into a user’s current theme’s header file alongside another JavaScript, aiming to take control of the site. 

“The most important thing you can do in a situation like this is to keep your plug-ins up-to-date and to deactivate and delete any plug-ins that have been removed from the WordPress plug-in repository. The vast majority of these attacks are targeted at vulnerabilities that were patched months or years ago, and in plug-ins that don’t have a large number of users,” Gall advised.

“While we did not see any attacks that would be effective against the latest versions of any currently available plug-ins, running a web application firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” he added.

Hot this week

OPPO partners with football prodigy Lamine Yamal as global ambassador

OPPO announces Lamine Yamal as global ambassador, combining football and technology to inspire young people through the "Make Your Moment" campaign.

Seagate unveils 36TB hard drives, expanding its Mozaic 3+ technology

Seagate introduces Exos M hard drives with up to 36TB capacity, powered by HAMR technology, offering unmatched scale, efficiency, and innovation for AI and data centres.

Business leaders show optimism for 2025 with plans for investment in innovation, efficiency, and resilience

Business leaders are optimistic for 2025, focusing on innovation, efficiency, and sustainability, while navigating uncertainty with increased investments.

DXC and Ferrari join forces for next-gen vehicle technology

DXC partners with Ferrari to create next-gen infotainment systems, including the F80โ€™s advanced digital cockpit for road and track use.

TikTok services were restored in the US after a brief shutdown

TikTok restored its service in the US after a brief outage following former President Trumpโ€™s executive action to delay a looming nationwide ban.

Garmin launches Instinct 3 Series smartwatches with AMOLED displays

Garmin unveils the Instinct 3 Series, rugged smartwatches with AMOLED displays, solar charging, advanced health monitoring, and military-grade durability.

UK unveils digital wallet and AI chatbot to revolutionise public services

The UK announces a digital wallet for IDs and an OpenAI-powered chatbot to enhance public services, aiming for secure and efficient solutions.

Apple set to launch iPhone SE 4 with Dynamic Island and iPad Air featuring M3 chip

The iPhone SE 4 with Dynamic Island and iPad Air with M3 chip are expected to launch soon. They will offer modern design and performance upgrades.

President Trump signs executive order delaying TikTok ban for 75 days

Trump delayed the TikTok ban with a 75-day executive order, allowing time to address national security concerns and find a resolution.

Related Articles