WordPress UpdraftPlus update immediately

Millions of WordPress sites needed to be updated and the reason was a vulnerability in UpdraftPlus, a popular plugin that allows users to create and restore .

The developers of UpdraftPlus requested the mandatory update, as the vulnerability allowed anyone with to download a website's entire database.

updraftplus

The bug was discovered by Jetpack security researcher Marc Montpas during a security of the plugin.

"Αυτό το σφάλμα είναι πολύ εύκολο να το εκμεταλλευτεί κανείς, με πολύ άσχημα αποτελέσματα. Δίνει τη δυνατότητα σε χρήστες χαμηλών προνομίων να κατεβάσουν ασφαλείας ενός ιστότοπου, τα οποία περιλαμβάνουν ακατέργαστα αντίγραφα ασφαλείας της βάσης δεδομένων".

He reported the bug to the UpdraftPlus developers on Tuesday last week, they fixed it a day later and immediately started the forced installation of the update.

1,7 million sites have been updated since Thursday, out of a total of 3 million users using the plugin.

The main flaw was that UpdraftPlus didn't properly implement WordPress' "hearbeat" feature and couldn't check if users had admin rights. Another issue was a variable used to authenticate administrators to distinguish them from untrusted users. For those interested Jetpack posted more details for the hack.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
WordPress, UpdraftPlus, iguru

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).