Hackers exploit critical vulnerability found in ~100,000 WordPress sites

Flaw in ThemeGrill plugin lets attackers wipe sites clean and possibly take them over. …

Image of ones and zeros with the word reader comments

27 with 23 posters participating

Hackers are actively exploiting a critical WordPress plugin vulnerability that allows them to completely wipe all website databases and, in some cases, seize complete control of affected sites.

The flaw is in the ThemeGrill Demo Importer installed on some 100,000 sites, and it was disclosed over the weekend by Website security company WebARX. By Tuesday, WebArx reported that the flaw was under active exploit with almost 17,000 attacks blocked so far. Hanno Böck, a journalist who works for Golem.de, also spotted active attacks and reported them on Twitter.

“There’s currently a severe vuln in a wordpress plugin called “themegrill demo importer” that resets the whole database,” Böck wrote. “https://webarxsecurity.com/critical-issue-in-themegrill-demo-importer/ It seems attacks are starting: Some of the affected webpages show a wordpress ‘hello world’-post. /cc If you use this plugin and your webpage hasn’t been deleted yet consider yourself lucky. And remove the plugin. (Yes, remove it, don’t just update.)”

Hello, cruel world

The “Hello World” message is the default placeholder displayed on WordPress sites when the open source content-management system is first installed or when it’s wiped clean. Böck told me that attackers appear to be exploiting the ThemeGrill vulnerability in hopes of gaining administrative control over affected websites. Website takeovers only occur when a vulnerable site has an account with the name “admin.” In those cases, after hackers exploit the vulnerability and wipe

Continue reading – Article source

Similar Posts: