International Business Weekly
  • Home
  • News
  • Politics
  • Business
  • National
  • Culture
  • Lifestyle
  • Sports
No Result
View All Result
  • Home
  • News
  • Politics
  • Business
  • National
  • Culture
  • Lifestyle
  • Sports
No Result
View All Result
International Business Weekly
No Result
View All Result
Home National

WordPress websites at risk; over 2 lakh sites vulnerable to hacking due to plugin bug [details]

July 2, 2023
in National
0
WordPress websites at risk; over 2 lakh sites vulnerable to hacking due to plugin bug [details]
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter


5.4 mn users’ data exposed online as Musk reveals Twitter 2.0







More than 2 lakh WordPress websites are at the hacking risk due to a critical unpatched security vulnerability that was being actively exploited by malicious actors.

According to WordPress security firm WPScan, the bug is present in the Ultimate Member plugin, which is a free user profile WordPress plugin that makes it easy to create powerful online communities and membership sites with WordPress.

“This is a very serious issue as unauthenticated attackers may exploit this vulnerability to create new user accounts with administrative privileges, giving them the power to take complete control of affected sites,” the security firm warned.

IANS

There was “no complete fix to this issue” and worryingly, “there were indications that this issue was being actively exploited by malicious actors,” the firm added.

In response to the vulnerability report, the creators of the plugin promptly released a new version, 2.6.4, intending to fix the problem.

“However, upon investigating this update, we found numerous methods to circumvent the proposed patch, implying the issue is still fully exploitable,” the WPScan team noted.

The plugin operates by using a pre-defined list of user metadata keys that users should not manipulate.

Zomato hacking

Reuters

It uses this list to check if users are attempting to register these keys when creating an account.

“Unfortunately, differences in how the Ultimate Member’s blocklist logic and how WordPress treats metadata keys made it possible for attackers to trick the plugin into updating some it shouldn’t,” said the team.

The security researchers recommend that the users should disable the Ultimate Member plugin until a patch that completely remediates this security issue is made available.

Sites on WP.cloud hosts, such as WordPress.com and Pressable.com, have received a platform-level patch to help mitigate the vulnerability.

(With inputs from IANS)



Source link

Tags: 2 lakh wordpress websites riskbugdetailsDuehackinglakhPluginRisksitesvulnerablewebsiteswordpresswordpress bugwordpress hackingwordpress riskwordpress websites plugin bugwordpress websites risk
Brand Post

Brand Post

I am an editor for IBW, focusing on business and entrepreneurship. I love uncovering emerging trends and crafting stories that inspire and inform readers about innovative ventures and industry insights.

Related Posts

Harvard Physicist Claims 3I/ATLAS Object Is ‘Not Natural’: Why He Is Baffled
National

Harvard Physicist Claims 3I/ATLAS Object Is ‘Not Natural’: Why He Is Baffled

November 15, 2025
ESA Uses Mars Rover Data To Track Comet 3I/ATLAS: Accuracy Leaps Ten-Fold
National

ESA Uses Mars Rover Data To Track Comet 3I/ATLAS: Accuracy Leaps Ten-Fold

November 15, 2025
Classified DOJ Authorizing Strikes On Alleged Drug Boats Describes Fentanyl As a Potential Chemical Weapons Threat: Report
National

Classified DOJ Authorizing Strikes On Alleged Drug Boats Describes Fentanyl As a Potential Chemical Weapons Threat: Report

November 15, 2025
Next Post
Biden To Travel To UK, NATO Summit, Finland: White House

Biden To Travel To UK, NATO Summit, Finland: White House

Dr. Romantic 4 Renewal: Cast Members Tease New Sequel

Dr. Romantic 4 Renewal: Cast Members Tease New Sequel

Zulu King Undergoes Tests Following Adviser’s Sudden Death: Spokesman

Zulu King Undergoes Tests Following Adviser's Sudden Death: Spokesman

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ABOUT US

International Business Weekly is an American entertainment magazine. We cover business News & feature exclusive interviews with many notable figures

Copyright © 2024 - International Business Weekly

  • About
  • Advertise
  • Careers
  • Contact
No Result
View All Result
  • Home
  • Politics
  • News
  • Business
  • Culture
  • National
  • Sports
  • Lifestyle
  • Travel

Copyright © 2024 - International Business Weekly

سایت کازینو,سایت کازینو انفجار,سایت انفجار هات بت,سایت حضرات ,بت خانه ,تاینی بت ,سیب بت ,ایس بت بدون فیلتر ,ماه بت ,دانلود اپلیکیشن دنس بت ,بازی انفجار دنس,ازا بت,ازا بت,اپلیکیشن هات بت,اپلیکیشن هات بت,عقاب بت,فیفا نود,شرط بندی سنگ کاغذ قیچی,bet90,bet90,سایت شرط بندی پاسور,بت لند,Bababet,Bababet,گلف بت,گلف بت,پوکر آنلاین,پاسور شرطی,پاسور شرطی,پاسور شرطی,پاسور شرطی,تهران بت,تهران بت,تهران بت,تخته نرد پولی,ناسا بت ,هزار بت,هزار بت,شهر بت,چهار برگ آنلاین,چهار برگ آنلاین,رد بت,رد بت,پنالتی بت,بازی انفجار حضرات,بازی انفجار حضرات,بازی انفجار حضرات,سبد ۷۲۴,بت 303,بت 303,شرط بندی پولی,بتکارت بدون فیلتر,بتکارت بدون فیلتر,بتکارت بدون فیلتر, بت تایم, سایت شرط بندی بدون نیاز به پول, یاس بت, بت خانه, Tatalbet, اپلیکیشن سیب بت, اپلیکیشن سیب بت, بت استار, پابلو بت, پیش بینی فوتبال, بت 45, سایت همسریابی پيوند, بت باز, بری بت, بازی انفجار رایگان, شير بت, رویال بت, بت فلاد, روما بت, پوکر ریور, تاس وگاس, بت ناب, بتکارت, سایت بت برو, سایت حضرات, سیب بت, پارس نود, ایس بت, سایت سیگاری بت, sigaribet, هات بت, سایت هات بت, سایت بت برو, بت برو, ماه بت, اوزابت | ozabet, تاینی بت | tinybet, بری بت | سایت بدون فیلتر بری بت, دنس بت بدون فیلتر, bet120 | سایت بت ۱۲۰, ace90bet | acebet90 | ac90bet, ثبت نام در سایت تک بت, سیب بت 90 بدون فیلتر, یاس بت | آدرس بدون فیلتر یاس بت, بازی انفجار دنس, بت خانه | سایت, بت تایم | bettime90, دانلود اپلیکیشن وان ایکس بت 1xbet بدون فیلتر و آدرس جدید, سایت همسریابی دائم و رایگان برای یافتن بهترین همسر و همدم, دانلود اپلیکیشن هات بت بدون فیلتر برای اندروید و لینک مستقیم, تتل بت - سایت شرط بندی بدون فیلتر, دانلود اپلیکیشن بت فوت - سایت شرط بندی فوت بت بدون فیلتر, سایت بت لند 90 و دانلود اپلیکیشن بت 90, سایت ناسا بت - nasabet, دانلود اپلیکیشن ABT90 - ثبت نام و ورود به سایت بدون فیلتر, https://planer4.com/, http://geduf.com/,, بازی انفجار, http://foreverliving-ar.com/, https://wediscusstech.com/, http://codesterlab.com/, https://www.9ja4u.com/, https://pimpurwhip.com/, http://nubti.com/, http://www.casinoherrald.com/, http://oigor.com/, http://coinjoin.art/, بازی مونتی