EssentialPlugin Vulnerability: Critical Exploit in 20+ Plugins

Date:

WordPress Vulnerability Report: Supply Chain Compromise in EssentialPlugin

A serious security vulnerability has been identified in multiple WordPress plugins developed by EssentialPlugin. Following the acquisition of the company, a malicious actor embedded a backdoor in over 20 plugins, allowing them to distribute malware to thousands of WordPress sites.

Vulnerability Explanation: This incident, known as a supply chain compromise, occurred when the new owner activated a dormant backdoor disguised as a routine update. This backdoor could execute commands and write arbitrary files on affected sites.

Affected Component: The compromised plugins include popular options like WP Logo Showcase and Countdown Timer.

Impact: If left unaddressed, these vulnerabilities could lead to complete site compromise.

Fix: Users should immediately update their plugins to the latest versions. The WordPress Plugin Review team has removed the affected plugins and implemented security measures.

Risk Level: High. Site administrators are urged to act swiftly to protect their sites.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...