Monday, 16 June 2025
27.8 C
Singapore
30.4 C
Thailand
19.6 C
Indonesia
28.2 C
Philippines

Over a million WordPress sites attacked by a hacker in a month

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher.  The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over […]

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher. 

The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over 500,000 individual sites, according to Ram Gall from Wordfence.

Over the past month, Wordfence, a security vendor, detected attacks on over 900,000 sites from more than 24,000 IP addresses, all of which appear to be from the same malicious hacker. That is because the attacker is attempting to inject a similar JavaScript payload to insert a backdoor into a victim website and redirect visitors.

The attacks seek to exploit a few cross-site scripting vulnerabilities in the Newspaper theme, Easy2Map plug-in, and the Blog Designer plug-in. It also targeted the WP GDPR Compliance plug-in as well as the Total Donations plug-in.

Gall warned that the hacker behind all this might be able to pivot other vulnerabilities in the future.

The JavaScript used to attack the sites is designed to redirect users who are not logged-in to a malvertising URL. If the users are logged-in, the JavaScript tries to inject a malicious backdoor into a user’s current theme’s header file alongside another JavaScript, aiming to take control of the site. 

“The most important thing you can do in a situation like this is to keep your plug-ins up-to-date and to deactivate and delete any plug-ins that have been removed from the WordPress plug-in repository. The vast majority of these attacks are targeted at vulnerabilities that were patched months or years ago, and in plug-ins that don’t have a large number of users,” Gall advised.

“While we did not see any attacks that would be effective against the latest versions of any currently available plug-ins, running a web application firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” he added.

Hot this week

Steam adds full native support for Apple Silicon Macs

Steam runs natively on Apple Silicon Macs, ditching Rosetta 2 for smoother performance and better gaming on M1 and M2 devices.

SEON unveils AI-powered AML suite to unify fraud and compliance efforts

SEON launches AI-powered AML suite with real-time monitoring, helping risk teams manage fraud and compliance from one unified platform.

Proofpoint opens new Singapore office to expand APAC operations and AI capabilities

Proofpoint opens new Singapore office to expand APAC presence and boost AI-led, human-centric cybersecurity efforts across the region.

CMF Phone 2 Pro review: Playful power meets practical design

CMF Phone 2 Pro blends standout design, smooth performance and creative features into a lightweight phone that’s fun and practical to use.

Disinformation security: Safeguarding truth in the digital age

Discover how AI detection tools, public education, and smart regulations are working together to combat the spread of misinformation online.

Meta brings sponsored content to WhatsApp

WhatsApp shows ads in the Status feature and promoted channels, but your private chats and messages will stay ad-free.

Anker recalls over 1.1 million power banks due to fire risk: Check if yours is one of them

Anker is recalling over 1.1 million PowerCore power banks due to fire risks. Check your model number and serial number to stay safe.

Nubia introduces Pad Pro to shake up Android tablet market with low price and high specs

Nubia Pad Pro launches globally with powerful specs, a sleek design, and a low starting price of US$419, rivalling big-name Android tablets.

Taiwan tightens export controls on Huawei and SMIC over security concerns

Taiwan placed export controls on Huawei and SMIC, adding them to a restricted list that could stall China's AI chip production efforts.

Related Articles

Popular Categories