WordPress Social Warfare plugin vulnerabilities abused in the wild
#1
Quote:About 42,000 websites have not updated to the latest version of the Social Warfare WordPress plugin, leaving themselves open to a pair of vulnerabilities that are being exploited in the wild.
 
Palo Alto’s Unit 42 research team is reporting that the two problems, both rated medium-level threats and tracked under CVE-2019-9978, were patched through a release posted on March 21. But any site that has not updated could be hit with a remote code execution or cross-site scripting attack. Versions 3.5.3 and earlier of Social Warfare, which adds social sharing buttons to websites, are at issue.
 
“An attacker can use these vulnerabilities to run arbitrary PHP code and control the website and the server without authentication. The attackers may use the compromised sites to perform digital coin mining or host malicious exploit code,” Unit 42 wrote.

In tracking the threat, the researchers found five compromised sites that are actively being used for hosting malicious exploit code.

SOURCE: https://www.scmagazine.com/home/security...-the-wild/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Tor Browser 15.0.12
 Tor Browser 15.0....harlan4096 — 12:26
Mozilla Firefox Browser 150.0.2
Mozilla Firefox Br...harlan4096 — 10:49
AMD Radeon Adrenalin Edition 26.5.1
AMD Radeon Adrenal...harlan4096 — 10:48
AdGuard for iOS v4.5.20
AdGuard for iOS v4...harlan4096 — 10:46
Google Chrome 148.0.7778.96/97
Google Chrome 148....harlan4096 — 10:45

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>