• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
researchers find backdoor in school management plugin for wordpress

Researchers Find Backdoor in School Management Plugin for WordPress

You are here: Home / General Cyber Security News / Researchers Find Backdoor in School Management Plugin for WordPress
May 21, 2022

Multiple versions of a WordPress plugin by the title of “Faculty Administration Pro” harbored a backdoor that could grant an adversary total regulate above vulnerable internet sites.

The issue, noticed in premium variations in advance of 9.9.7, has been assigned the CVE identifier CVE-2022-1609 and is rated 10 out of 10 for severity.

The backdoor, which is thought to have existed given that model 8.9, permits “an unauthenticated attacker to execute arbitrary PHP code on web sites with the plugin set up,” Jetpack’s Harald Eilertsen stated in a Friday produce-up.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Faculty Administration, formulated by an India-based enterprise identified as Weblizar, is billed as a WordPress increase-on to “deal with finish school operation.” It also promises extra than 340,000 consumers of its quality and totally free WordPress themes and plugins.

The WordPress security company mentioned that it uncovered the implant on May 4 just after it was alerted to the presence of closely obfuscated code in the license-examining code of the plugin. The no cost variation of School Management, which does not pack the licensing code, is not impacted.

CyberSecurity

Whilst the backdoor has because been taken off, the precise origins of the compromise remains unclear, with the seller stating that “they do not know when or how the code arrived into their application.”

Customers of the plugin are advisable to update to the latest model (9.9.7) to prevent active exploitation tries.

Observed this short article attention-grabbing? Adhere to THN on Fb, Twitter  and LinkedIn to study much more distinctive content we write-up.


Some components of this post are sourced from:
thehackernews.com

Previous Post: «cisco issues patch for new ios xr zero day vulnerability exploited Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited in the Wild
Next Post: Why don’t we ever hear about ransomware demands in the tens of millions of dollars? why don’t we ever hear about ransomware demands in the»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.