Attacks on over 300.000 vulnerable WordPress pages

Attackers take advantage of a critical remote code execution flaw that affects over 600.000 WordPress sites. The vulnerability we mentioned in a previous publication and concerns websites that run vulnerable versions of the File Manager plugin.

Critical vulnerability allows unauthorized to upload maliciously PHP and run malicious code. The File Manager development team addressed the flaw with the release of File Manager 6.9.

Although the bug was fixed immediately when developers were notified by Seravo security manager Ville Korhonen, who discovered the 0day and the ongoing attacks that were trying to exploit it, by security firm Defiant found more than 1,7 million vulnerable websites from September 1st to September 3rd.

In an updated report released today, Defiant threat analyst Ram Gall states that they have not stopped their "siege", and the total number of WordPress sites they are targeting has reached 2,6 million.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).