• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
experts notice sudden surge in exploitation of wordpress page builder

Experts Notice Sudden Surge in Exploitation of WordPress Page Builder Plugin Vulnerability

You are here: Home / General Cyber Security News / Experts Notice Sudden Surge in Exploitation of WordPress Page Builder Plugin Vulnerability
July 18, 2022

Scientists from Wordfence have sounded the alarm about a “unexpected” spike in cyber attacks attempting to exploit an unpatched flaw in a WordPress plugin referred to as Kaswara Modern-day WPBakery Webpage Builder Addons.

Tracked as CVE-2021-24284, the issue is rated 10. on the CVSS vulnerability scoring technique and relates to an unauthenticated arbitrary file upload that could be abused to acquire code execution, allowing attackers to seize handle of afflicted WordPress websites.

Although the bug was initially disclosed in April 2021 by the WordPress security business, it continues to continue to be unresolved to date. To make matters even worse, the plugin has been shut and is no more time actively maintained.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Wordfence, which is preserving around 1,000 web-sites that have the plugin installed, explained it has blocked an common of 443,868 attack tries for each working day considering the fact that the start off of the month.

WordPress Page Builder Plugin Vulnerability

The attacks have emanated from 10,215 IP addresses, with a the vast majority of the exploitation attempts narrowed down to 10 IP addresses. These entail uploading a ZIP archive made up of a destructive PHP file that permits the attacker to upload rogue data files to the contaminated site.

CyberSecurity

The target of the marketing campaign, it appears, is to insert code into or else reputable JavaScript documents and redirect internet site visitors to destructive web-sites. It is really worth noting that the attacks have been tracked by Avast and Sucuri beneath the monikers Parrot TDS and NDSW, respectively.

Among 4,000 and 8,000 web sites are mentioned to have the plugin put in, building it critical that people clear away it from their WordPress web-sites to thwart probable attacks and discover an appropriate alternative.

Identified this short article fascinating? Stick to THN on Facebook, Twitter  and LinkedIn to study a lot more distinctive material we submit.


Some areas of this post are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Tor Browser Adds Automatic Censorship Circumvention
Next Post: Pegasus Spyware Used to Hack Devices of Pro-Democracy Activists in Thailand pegasus spyware used to hack devices of pro democracy activists in»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.