A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Continue reading
- New Hacker Tools
- Hack Tool Apk No Root
- Best Pentesting Tools 2018
- Pentest Tools Linux
- Hak5 Tools
- Tools 4 Hack
- Pentest Tools Port Scanner
- Hacking Tools Mac
- Hack Tools Mac
- Hack Tools 2019
- Pentest Tools For Ubuntu
- Physical Pentest Tools
- Hack Website Online Tool
- Hacker Hardware Tools
- Growth Hacker Tools
- Pentest Tools Website
- Hacking Tools 2019
- Hacking App
- Pentest Tools Subdomain
- Hack Tools
- Computer Hacker
- Hacking Tools For Mac
- Hacking Tools Mac
- Hacking Tools And Software
- Pentest Tools Android
- Pentest Tools Windows
- Hack Tools For Ubuntu
- Pentest Tools
- Pentest Tools For Android
- Hacker Tools Windows
- Best Hacking Tools 2019
- Black Hat Hacker Tools
- Pentest Tools Apk
- Hack Tools For Ubuntu
- Kik Hack Tools
- Best Pentesting Tools 2018
- Black Hat Hacker Tools
- Hack Tools Github
- Pentest Tools Apk
- Beginner Hacker Tools
- Android Hack Tools Github
- Underground Hacker Sites
- Tools 4 Hack
- Hack Website Online Tool
- Game Hacking
- New Hack Tools
- Physical Pentest Tools
- Best Pentesting Tools 2018
- Usb Pentest Tools
- Hacker Tools For Pc
- Pentest Tools Tcp Port Scanner
- Pentest Automation Tools
- Hacker Tools Free
- Pentest Automation Tools
- Hacker Techniques Tools And Incident Handling
- Ethical Hacker Tools
- Hack Tools For Ubuntu
- Pentest Tools For Mac
- Hack Tools 2019
- Hacking Tools For Windows
- Android Hack Tools Github
- Hacking Tools Pc
- Nsa Hack Tools Download
- Pentest Tools Download
- Pentest Tools Open Source
- Beginner Hacker Tools
- Pentest Tools Kali Linux
- Hack And Tools
- Hacking Tools For Windows 7
- Hack Tools Online
- Hacker Tools Free Download
- Hacker Tools Hardware
- Hacking Tools For Windows Free Download
- Hak5 Tools
- Pentest Recon Tools
- Pentest Recon Tools
- Hack Tools For Games
- Hack App
- Hack Tools For Windows
- Hacker Tool Kit
- Usb Pentest Tools
- Pentest Tools Alternative
- Pentest Tools Github
- Hack Tools Pc
- Pentest Tools Website
- Pentest Tools Android
- Hacking Tools Online
- Pentest Tools Subdomain
- Hackers Toolbox
- Tools Used For Hacking
- Physical Pentest Tools
- Hacker
- Hacker Tools 2019
- Hacking Tools Online
- How To Make Hacking Tools
- Hacker Tools List
- Computer Hacker
- Pentest Tools For Windows
- Hacking Tools For Windows Free Download
- Hacker Hardware Tools
- Nsa Hacker Tools
- Hack Tool Apk
- Pentest Tools Linux
- Pentest Tools For Mac
- Pentest Tools Url Fuzzer
- Hacking Tools For Pc
- Physical Pentest Tools
- Pentest Tools Android
- Hacker Tools For Mac
- Pentest Tools List
- Game Hacking
- Nsa Hack Tools Download
- Hacker Tools Apk
- Hacker Tools Free Download
- Pentest Tools List
- Tools 4 Hack
- Pentest Tools Port Scanner
- Tools 4 Hack
- Hacking Tools For Windows
- Termux Hacking Tools 2019
- Pentest Box Tools Download
- Hacker Tools For Ios
- Hack And Tools
- Hacking Tools Kit
- Hacking Tools For Beginners
- Hacking Tools For Beginners
- Hack Tools
- Hacking Tools Online
- Hacking Tools Name
0 komentar:
Posting Komentar