Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Critical WordPress plugin vulnerability exposes more than 4 million sites
Global Security

Critical WordPress plugin vulnerability exposes more than 4 million sites

AdminBy AdminNovember 18, 2024No Comments2 Mins Read
WordPress Plugin Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 18, 2024Ravi LakshmananWebsite Vulnerability / Security

WordPress plugin vulnerability

A critical authentication bypass vulnerability has been discovered in the Really Simple Security (formerly Really Simple SSL) WordPress plugin that, if successfully exploited, could give an attacker remote full administrative access to a vulnerable site.

The vulnerability, identified as CVE-2024-10924 (CVSS score: 9.8), affects both the free and premium versions of the plugin. The software is installed on over 4 million WordPress sites.

“The vulnerability is scriptable, meaning it can be turned into a large-scale automated attack targeting WordPress websites,” said István Martan, security researcher at Wordfence. said.

Cyber ​​security

After a responsible disclosure on November 6, 2024, the flaw was fixed in version 9.1.2, released a week later. This is a risk of possible abuse prompted plugin developers must work with WordPress to force all sites running the plugin to update to public disclosure.

According to Wordfence, the authentication bypass vulnerability discovered in versions 9.0.0 to 9.1.1.1 is due to incorrect handling of user validation errors in a function called “check_login_and_get_user”, which allows unauthenticated attackers to log in as arbitrary users, including number of administrators when two-factor authentication is enabled.

WordPress plugin vulnerability

“Unfortunately, one of the features that adds two-factor authentication was implemented insecurely, allowing unauthenticated attackers to gain access to any user account, including an administrator account, with a simple query with two-factor authentication enabled,” Marton said.

Successful exploitation of the vulnerability could have serious consequences as it could allow attackers to hijack WordPress sites and further use them for criminal purposes.

The disclosure comes days after Wordfence discovered another critical flaw in the WPLMS learning management system for WordPress, WordPress LMS (CVE-2024-10470, CVSS Score: 9.8), which could allow unauthenticated threat actors to read and delete arbitrary files, potentially leading to code execution.

Cyber ​​security

Specifically, the theme prior to version 4.963 is “vulnerable to arbitrary file reading and deletion due to insufficient file path and permission validation,” allowing unauthenticated attackers to delete arbitrary files on the server.

“This allows an unauthenticated attacker to read and delete any arbitrary file on the server, including the site’s wp-config.php file,” it said. said. “Deleting wp-config.php forces the site into a configuration state, which allows an attacker to initiate a site hijack by connecting it to a database under their control.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025

Fedramp at starting speed: obtained lessons

June 18, 2025

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.