Hackers exploit critical vulnerability found in ~100,000 WordPress sites
Flaw in ThemeGrill plugin lets attackers wipe sites clean and possibly take them over. …
reader comments
27 with 23 posters participating
Hackers are actively exploiting a critical WordPress plugin vulnerability that allows them to completely wipe all website databases and, in some cases, seize complete control of affected sites.
The flaw is in the ThemeGrill Demo Importer installed on some 100,000 sites, and it was disclosed over the weekend by Website security company WebARX. By Tuesday, WebArx reported that the flaw was under active exploit with almost 17,000 attacks blocked so far. Hanno Böck, a journalist who works for Golem.de, also spotted active attacks and reported them on Twitter.
If you use this plugin and your webpage hasn’t been deleted yet consider yourself lucky. And remove the plugin. (Yes, remove it, don’t just update.)
— hanno (@hanno) February 18, 2020
“There’s currently a severe vuln in a wordpress plugin called “themegrill demo importer” that resets the whole database,” Böck wrote. “https://webarxsecurity.com/critical-issue-in-themegrill-demo-importer/ It seems attacks are starting: Some of the affected webpages show a wordpress ‘hello world’-post. /cc If you use this plugin and your webpage hasn’t been deleted yet consider yourself lucky. And remove the plugin. (Yes, remove it, don’t just update.)”
Hello, cruel world
The “Hello World” message is the default placeholder displayed on WordPress sites when the open source content-management system is first installed or when it’s wiped clean. Böck told me that attackers appear to be exploiting the ThemeGrill vulnerability in hopes of gaining administrative control over affected websites. Website takeovers only occur when a vulnerable site has an account with the name “admin.” In those cases, after hackers exploit the vulnerability and wipe
Continue reading – Article source