WordPress Websites Security Issues Expose Millions of Sites to Hackers

TechnologyWordPress Websites Security Issues Expose Millions of Sites to Hackers

Internet is under the threat of WordPress websites security issues due to a recent attack on the plugin. WordPress is a host plugin for more than one million websites all around the world. Thus, this recent attack has increased the vulnerability of all the websites to face some malicious activities to the site as well as the computer. Essential Addons for Elementors has carried this attack to WordPress.

Basically, Essential Addons For Elementors is an extension for WordPress. Essential addons for Elementors provide easy-to-use elements to the users. This elementor plugin was carrying a critical Remote Code Execution (RCE). This RCE is a flaw that allows the local file inclusion vulnerability that allows attackers to get access to the unauthorized files on your website.

What is The WordPress Websites Security Issue?

WordPress websites security issues

RCE attack is a malware function that allows the attackers to integrate a code into your system. The code can cause malfunction in your website to allow the malicious attackers to access files in your website and computer.

The cyber security researcher, Wai Yan Muo Thet on January 25th, 2022. He reported about this attack to PatchStack. PatchStack is a security plugin that safeguards WordPress from plugin vulnerabilities. PatchStack also got a virtual update on the same date.

Before this attack became viral, the owners of WPDevelopers had predicted this situation and tried their best to avoid it. But, two of their attempts became unsuccessful in preventing this malicious attack.

PatchStack Involvement

WordPress websites security issues

PatchStack clarified that the attack occurred because of the use of dynamic gallery and product gallery widgets. Both these widgets have vulnerability functions which caused the WordPress websites security issues.

It also stated, “This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack. This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed.”

To mitigate this vulnerability, the updated versions 5.0.0 and 5.0.4 plugins tried to resolve the issue bit in vain. Then, the researchers introduced a different version which is 5.0.5 that resolved the issue.

As a large number of websites use Essential Addons for Elementor, the version has tried to curb the issue. According to reports, 400,00 websites have updated their patch version while the rest of them still remain under threat of vulnerability. If they update their version, they can protect their systems and websites from this WordPress websites security issues.

Duaa Naeem
Duaa Naeem
Dua is a seasoned writer who loves to write on Pakistani Entertainment and Infotainment while having her Masters in English literature

Must read

Recent News

Moscow says it won’t allow US to silence UNSC on Israeli violence against Palestinians Monitoring Desk: Russian envoy in United Nations Vasily Nebenzya said that the UN Security Council should bring peace, stability and prosperity to the Middle East and Russia would not allow United States to silence UNSC over the issue of Gaza crisis. According to TASS news Agency, Nebenzya said that Moscow will continue to call for an end to violence against Palestinians and will not allow the US to muzzle the UN Security Council as Washington seeks to support Israel's operation in Gaza. "We will continue to stand firmly for ending violence against the Palestinians. Without a shadow of a doubt, we will continue to expose the abuses and sanctimony with which the US is handling the situation. We will not allow the Americans to gag the entire council with their hands in an effort to encourage further continuation of Israel's ruthless operation," he said in a speech at the Security Council.

Moscow won’t allow the US to silence the UNSC on Israeli violence against Palestinians

0
Monitoring Desk: Russian envoy to the United Nations Vasily Nebenzya said that the UN Security Council should bring peace, stability, and prosperity to the...

From Valdai to Margalla Dialogue —- All roads to Civilisations go through Islamabad

0
By Shazia Anwer CheemaThe emergent realities of global security are fundamentally transforming the frame of references and trajectorial approaches toward them. New security architecture...

12 more men in uniform embraced martyrdom for the motherland in Pakistan

0
Monitoring Desk: 12 more men in uniform embraced martyrdom for the motherland in Pakistan, said Inter Service Public Relations (ISPR) of the Pakistan Army.On...
Dr. Attia Anwar

Lifelong learning

0
By Dr. Attia AnwarAs we age, our minds and mental health become more important. We should try to maintain and improve them. Education is...
12th Defense Expo 'Ideas 2024' 'Weapons for Peace' a major step in defense diplomacy

12th Defense Expo ‘Ideas 2024’ ‘Weapons for Peace’ a major step in defense diplomacy

0
By Asghar Ali MubarakIdeas 2024, the global exhibition of defense equipment, will begin today at the Karachi Expo Center on November 19, in which...
Advertisement