• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
wordpress admins urged to remove miniorange plugins due to critical

WordPress Admins Urged to Remove miniOrange Plugins Due to Critical Flaw

You are here: Home / General Cyber Security News / WordPress Admins Urged to Remove miniOrange Plugins Due to Critical Flaw
March 18, 2024

WordPress people of miniOrange’s Malware Scanner and Web Application Firewall plugins are staying urged to delete them from their sites subsequent the discovery of a critical security flaw.

The flaw, tracked as CVE-2024-2172, is rated 9.8 out of a most of 10 on the CVSS scoring process. It impacts the next variations of the two plugins –

  • Malware Scanner (variations <= 4.7.2)
  • Web Application Firewall (versions <= 2.1.1)

It’s worth noting that the plugins have been permanently closed by the maintainers as of March 7, 2024. While Malware Scanner has over 10,000 active installs, Web Application Firewall has much more than 300 active installations.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“This vulnerability would make it achievable for an unauthenticated attacker to grant them selves administrative privileges by updating the user password,” Wordfence described very last week.

Cybersecurity

The issue is the final result of a missing capability test in the functionality mo_wpns_init() that allows an unauthenticated attacker to arbitrarily update any user’s password and escalate their privileges to that of an administrator, likely main to a full compromise of the site.

“The moment an attacker has obtained administrative consumer access to a WordPress website they can then manipulate everything on the focused web page as a standard administrator would,” Wordfence explained.

“This includes the means to upload plugin and theme files, which can be malicious zip documents containing backdoors, and modify posts and web pages which can be leveraged to redirect site users to other malicious internet sites or inject spam material.”

The development arrives as the WordPress security business warned of a equivalent high-severity privilege escalation flaw in the RegistrationMagic plugin (CVE-2024-1991, CVSS rating: 8.8) influencing all variations, together with and prior to 5.3…

The issue, resolved on March 11, 2024, with the release of edition 5.3.1., permits an authenticated attacker to grant themselves administrative privileges by updating the person function. The plugin has much more than 10,000 energetic installations.

“This vulnerability enables authenticated threat actors with subscriber-stage permissions or better to elevate their privileges to that of a web page administrator which could in the long run guide to comprehensive internet site compromise,” István Márton mentioned.

Located this report intriguing? Abide by us on Twitter  and LinkedIn to study much more special articles we article.


Some elements of this article are sourced from:
thehackernews.com

Previous Post: «apt28 hacker group targeting europe, americas, asia in widespread phishing APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme
Next Post: Hackers Using Sneaky HTML Smuggling to Deliver Malware via Fake Google Sites hackers using sneaky html smuggling to deliver malware via fake»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.