Search Results for: WordPress

Balada Injector Malware Campaign Detection: Hackers Exploit a tagDiv Composer Vulnerability Infecting Thousands of WordPress Sites
Balada Injector Malware Campaign Detection: Hackers Exploit a tagDiv Composer Vulnerability Infecting Thousands of WordPress Sites

Over a month ago, defenders warned the peer community of CVE-2023-4634, a critical WordPress vulnerability actively exploited in the wild and impacting an overwhelming number of WordPress sites across the globe. Following that campaign, another malicious operation comes to the forefront. A fresh surge in the long-lasting Balada Injector malware campaign has already impacted over […]

READ MORE
CVE-2023-4634 Detection: Unauthenticated RCE Vulnerability in WordPress Media Library Assistant Plugin
CVE-2023-4634 Detection: Unauthenticated RCE Vulnerability in WordPress Media Library Assistant Plugin

Security researchers have issued a stark warning about a critical vulnerability, designated as CVE-2023-4634, which is affecting an alarming number of over 70,000 WordPress sites globally. This vulnerability originates from a security flaw in the WordPress Media Library Assistant Plugin, an extremely popular and widely used plugin within the WordPress community. With this vulnerability already […]

READ MORE
XSS Hole Gives an Easy Way into WordPress
XSS Hole Gives an Easy Way into WordPress

Delaware, USA – March 13, 2019 – Extending WordPress capabilities with plugins doesn’t only widen the default functions but also brings a number of risks. Woocommerce Abandoned Cart Lite plugin provides a webadmin with the report of the products frequently bought from the site as well as the details about the shopping card list. However, […]

READ MORE
Zero-Day in Total Donations Plugin Allows to Compromise WordPress Websites
Zero-Day in Total Donations Plugin Allows to Compromise WordPress Websites

Delaware, USA – January 28, 2019 – A critical vulnerability was found in one of the popular WordPress commercial plugins, Wordfence reports. According to the published information, the Total Donations plugin contains an Ajax code which makes the whole WordPress site unsecured and enables remote malicious manipulations like changing core settings or even modifying the […]

READ MORE
‘Master134’ Abuses Thousands of Compromised WordPress Websites in Malvertising Campaign
‘Master134’ Abuses Thousands of Compromised WordPress Websites in Malvertising Campaign

Delaware, USA – July 31, 2018 – Experts from Check Point uncovered a large-scale malvertising campaign, which was used to redirect users to Exploit Kits landing pages and technical support scammers’ websites. During the investigation of one of the RIG EK campaigns, the researchers found the Master134 server, to which scripts on the hacked websites […]

READ MORE
Massive Brute Force Campaign Targets WordPress Sites
Massive Brute Force Campaign Targets WordPress Sites

Delaware, USA – December 21, 2017 – This Monday, Wordfence company reported on the start of massive brute force campaign against WordPress websites. There are more than 10,000 IPs from different countries involved in this attack. Employees of security firm recorded splashes exceeding 14 million attempts of password guessing per hour that targeted approximately 200,000 […]

READ MORE
Coinhive Injections in WordPress Sites
Coinhive Injections in WordPress Sites

Delaware, USA – October 31, 2017 – Coinhive remains the most popular platform for mining Monero cryptocurrency in user’s browsers. Despite the creation of a cryptocurrency miner modification, which allows users to control mining process in their browser and even disable it, the original version of the Coinhive JavaScript miner is actively used by attackers […]

READ MORE