Tag Archive for: plugin

WordPress sites hacked through defunct Rich Reviews plugin

An estimated 16,000 websites are believed to be running a vulnerable and no-longer-maintained WordPress plugin that can be exploited to display pop-up ads and redirect visitors to webpages containing porn, scams, and–worst of all–malware designed to infect users’ computers.

Read more in my article on the Tripwire State of Security blog.

Graham Cluley

Hackers actively exploit WordPress plugin flaw to send visitors to bad sites

A redirection from a site still running a vulnerable version of the plugin.

Enlarge / A redirection from a site still running a vulnerable version of the plugin.

Hackers have been actively exploiting a recently patched vulnerability in some websites that causes the sites to redirect to malicious sites or display misleading popups, security researchers warned on Wednesday.

The vulnerability was fixed two weeks ago in WP Live Chat Support, a plugin for the WordPress content management system that has 50,000 active installations. The persistent cross-site scripting vulnerability allows attackers to inject malicious JavaScript into sites that use the plugin, which provides an interface for visitors to have live chats with site representatives.

Researchers from security firm Zscaler’s ThreatLabZ say attackers are exploiting the vulnerability to cause sites using unpatched versions of WP Live Chat Support to redirect to malicious sites or to display unwanted popups. While the attacks aren’t widespread, there have been enough of them to raise concern.

Read 3 remaining paragraphs | Comments

Biz & IT – Ars Technica

WordPress Plugin Patched After Zero Day Discovered – Threatpost

WordPress Plugin Patched After Zero Day Discovered  Threatpost

The plugin, Social Warfare, is no longer listed after a cross site scripting flaw was found being exploited in the wild.

“zero day exploit” – read more

WordPress plugin zero day exploited in the wild | SC Media – SC Magazine

  1. WordPress plugin zero day exploited in the wild | SC Media  SC Magazine
  2. Social Warfare WordPress plugin exploited, affected many sites including us  Techaeris
  3. View full coverage on read more

“zero day exploit” – read more