Thursday, 28 August 2025
29.6 C
Singapore
31.8 C
Thailand
18.8 C
Indonesia
28.2 C
Philippines

Over a million WordPress sites attacked by a hacker in a month

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher.  The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over […]

WordPress users are being asked to make sure that all their plug-ins are up-to-date after a 30-fold increase in attack traffic targeting majorly cross-site scripting vulnerabilities were detected by a researcher. 

The surge in this malicious traffic over the last month peaked on May 3, 2020, when over 20 million attacks were attempted against over 500,000 individual sites, according to Ram Gall from Wordfence.

Over the past month, Wordfence, a security vendor, detected attacks on over 900,000 sites from more than 24,000 IP addresses, all of which appear to be from the same malicious hacker. That is because the attacker is attempting to inject a similar JavaScript payload to insert a backdoor into a victim website and redirect visitors.

The attacks seek to exploit a few cross-site scripting vulnerabilities in the Newspaper theme, Easy2Map plug-in, and the Blog Designer plug-in. It also targeted the WP GDPR Compliance plug-in as well as the Total Donations plug-in.

Gall warned that the hacker behind all this might be able to pivot other vulnerabilities in the future.

The JavaScript used to attack the sites is designed to redirect users who are not logged-in to a malvertising URL. If the users are logged-in, the JavaScript tries to inject a malicious backdoor into a user’s current theme’s header file alongside another JavaScript, aiming to take control of the site. 

“The most important thing you can do in a situation like this is to keep your plug-ins up-to-date and to deactivate and delete any plug-ins that have been removed from the WordPress plug-in repository. The vast majority of these attacks are targeted at vulnerabilities that were patched months or years ago, and in plug-ins that don’t have a large number of users,” Gall advised.

“While we did not see any attacks that would be effective against the latest versions of any currently available plug-ins, running a web application firewall can also help protect your site against any vulnerabilities that might have not yet been patched,” he added.

Hot this week

ITE and TP-Link sign partnership to boost enterprise tech skills in Singapore

ITE and TP-Link partner to launch new ICT training courses, equipping students with enterprise networking and security skills.

Apple shifts more iPhone production to India amid tariff concerns

Apple will ship its full iPhone 17 lineup from India for the first time, as it reduces reliance on China amid tariff tensions.

NVIDIA unveils Jetson Thor, its next-generation robotics computing platform

NVIDIA launches Jetson Thor, a next-gen AI robotics platform with 7.5x computing power, designed for developers and large-scale robotics projects.

Qualcomm introduces Snapdragon W5 Gen 2 chips with satellite support for smartwatches

Qualcomm launches Snapdragon W5 Gen 2 chips for smartwatches, featuring satellite support, enhanced GPS accuracy, and improved efficiency.

Microsoft brings Xbox Cloud Gaming to Game Pass Core and Standard tiers

Microsoft is testing Xbox Cloud Gaming for Game Pass Core and Standard members, adding PC titles and expanding access beyond Ultimate.

Microsoft’s Copilot AI to debut on Samsung TVs and monitors in 2025

Microsoft’s Copilot AI will launch on Samsung’s 2025 TVs and monitors, offering personalised support, recommendations, and voice-activated features.

Samsung to host virtual Unpacked event on 4 September

Samsung will host a virtual Unpacked event on 4 September, just before IFA Berlin, sparking speculation about new foldable devices.

WhatsApp introduces AI-powered Writing Help and Message Summaries in Singapore

WhatsApp launches Writing Help and Message Summaries in Singapore, offering AI-powered assistance with strong data privacy measures.

Bus Aunty review: Bringing bus arrival times into the home

Bus Aunty brings real-time bus arrival times into Singapore homes with an e-ink display, but quirks and pricing limit its appeal.

Related Articles

Popular Categories