• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

Critical WordPress Plugin Flaw Makes 400K Sites Vulnerable To Attack

by Cyber360 News
January 17, 2020
in Security
0
Critical WordPress Plugin Flaw Makes 400K Sites Vulnerable To Attack
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Researchers have found serious vulnerabilities in three WordPress plugins that have been installed on 400,000 websites — leaving them wide open for cyberattacks.

The bugs have been found in InfiniteWP, WP Time Capsule, and WP Database Reset plugins. These are similar types of authorization bypass bugs that allow anyone to access the backend of a website without passwords.

InfiniteWP Client

This plugin is the most severely affected by the authentication bypass vulnerability and more than 300,000 websites have InfiniteWP Client installed on them.

InfiniteWP Client basically allows administrators to manage multiple websites from a single server. However, by leveraging the flaw anyone can log in to an admin account without any credentials.

This would allow hackers to delete content, add new accounts, and execute a whole bunch of other malicious activities.

To exploit this vulnerability, one only requires the username of a valid account and inclusion of a malicious payload that is sent in a POST request to a vulnerable site.

This bug arises from a feature that lets users to automatically log in as an administrator without providing a password.

In case you are running InfiniteWP Client version 1.9.4.4 or lower on your website, you should update to 1.9.4.5 immediately.

WP Time Capsule

WP Time Capsule also suffers from an authentication bypass flaw that allows hackers to log in as admin. This plugin basically makes it easy to backup website data and about 20,000 websites have this plugin.

To leverage this flaw, attackers need to include a string in a POST request which helps them obtain a list of all admin accounts and automatically login to the first one.

A patch has been rolled out in version 1.21.16 so you should update your website right away if it is still running an earlier version.

WP Database Reset

The third bug was found in the WP Database Reset plugin which is installed in nearly 80,000 websites. It lets anyone reset the database to its original WordPress state within just a few clicks, thus wiping out all the data including posts, pages, users, and more.

The bug stems from reset functions that haven’t been secured by the standard capability checks or security nuances. The exploitation of this flaw can result in the complete loss of data or a site reset.

Another security flaw in WP Database Reset leads to a privilege-escalation vulnerability that lets any authenticated user (even those have restricted system rights) gain admin privileges and lock out all other users.

To avoid falling victim to such attacks, site administrators using this plugin should update to version 3.15 to patch both the bugs.

Amidst this potential threat, the only good news is that there’s no report of these vulnerabilities being exploited in the wild yet.

You can learn more about all the flaws here.

Cyber360 News

Cyber360 News

Next Post
Chinese police arrested the operator of unauthorized VPN service that made $1.6 million from his activity

Chinese police arrested the operator of unauthorized VPN service that made $1.6 million from his activity

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In