WordPress Elementor Pro attention update immediately

Hackers managed to locate one in a widely used WordPress plugin which enables them to take full control of millions of websites.

element pro

The vulnerability, which has a severity rating of 8,8 out of a possible 10, exists in the , ένα premium plugin που τρέχει σε περισσότερους από 12 εκατομμύρια ιστότοπους που υποστηρίζονται από το σύστημα of WordPress content.

Elementor Pro allows users to create high-quality websites using a wide range of tools, one of which is WooCommerce, a separate WordPress plugin. When these conditions are met, anyone with an account on the site — for example a non-privileged subscriber — can create new accounts that have full administrative rights.

The vulnerability was discovered by Jerome Bruandet, a researcher of security company NinTechNet. Last week, the developer of Elementor Pro released version 3.11.7, which fixes the problem. In a post published on Tuesday, Bruandet said:

An attacker can exploit the vulnerability to create an administrator account by enabling it (users_can_register) and setting the default role (default_role) to “administrator”, it can change the administrator email address (admin_email) or, as shown below, redirect all traffic to some external malicious site by changing the siteurl among other things:

screenshot 2023 04 01

Researchers from security firm PatchStack report that the is currently in active use. So if your blog is running the Elementor Pro plugin, upgrade immediately.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
WordPress, Elementor Pro

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).