A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Read more
- Hack Tools Download
- Hacker Tools Free Download
- Hacker Tool Kit
- Hack Tools Download
- Pentest Tools List
- Hacker Hardware Tools
- Pentest Tools Github
- Hacking Tools Name
- Pentest Box Tools Download
- Hacker Tools Free Download
- Pentest Tools Bluekeep
- Hacker Tools Software
- Hacker Tools Github
- World No 1 Hacker Software
- Nsa Hacker Tools
- Hacking Tools For Windows
- Hacker Hardware Tools
- How To Hack
- Hacker Tools For Windows
- Pentest Tools Download
- Ethical Hacker Tools
- Pentest Tools Android
- Hacking Tools Download
- Hack Tools For Mac
- Hacking Tools And Software
- Nsa Hack Tools
- New Hack Tools
- Hacker Tools Apk
- Hack Tools Pc
- Hacker
- Pentest Tools Alternative
- Computer Hacker
- Pentest Tools Open Source
- Hacking Tools For Mac
- Pentest Tools For Ubuntu
- Hack Tools For Mac
- Hacker Tools For Ios
- Hacking Tools For Windows
- Hacking Tools For Mac
- Pentest Tools Online
- Pentest Tools Apk
- Pentest Tools Find Subdomains
- Best Hacking Tools 2019
- Tools 4 Hack
- Hacker Tools Windows
- Hacking Tools 2020
- Hack Tools For Games
- Pentest Tools For Mac
- Hacking Tools For Beginners
- Android Hack Tools Github
- Hack Rom Tools
- Hacker Tools For Mac
- Hack Tools
- Pentest Tools
- Hacker Tools Linux
- Pentest Box Tools Download
- Tools 4 Hack
- Kik Hack Tools
- New Hacker Tools
- What Is Hacking Tools
- Pentest Tools For Windows
- Pentest Tools For Windows
- Hack Tools Pc
- Pentest Tools Kali Linux
- Hack Tools For Windows
- Hacker Tools For Windows
- Hacks And Tools
- Pentest Tools For Ubuntu
- Hack Tools For Pc
- Computer Hacker
- Hacker
- Game Hacking
- Github Hacking Tools
- Blackhat Hacker Tools
- Pentest Box Tools Download
- Hack Tools Mac
- Hacking Tools 2019
- Pentest Tools Framework
- Hacking Tools 2020
- Pentest Tools Linux
- Hacker Security Tools
- Hacker Tools For Ios
- Ethical Hacker Tools
- Hacks And Tools
- Hacker Security Tools
- Hacking Tools Github
- Hacks And Tools
- Pentest Tools Url Fuzzer
- Game Hacking
- Hack Tools
- Hack Tools Mac
- Pentest Tools Bluekeep
- Hack Tools 2019
- Hacking Tools For Mac
- Hacker Search Tools
- Pentest Tools Android
- Hacking Tools For Games
- Hack Tools For Mac
- Hack Tools Pc
- Hack Tools For Pc
- Pentest Tools Free
- Hacker Tools 2020
- Hacker Tools 2019
- New Hacker Tools
- Hacking Tools For Pc
- Best Hacking Tools 2020
- Nsa Hack Tools
- Hacker Search Tools
- Usb Pentest Tools
- Hak5 Tools
- How To Hack
- Growth Hacker Tools
- Pentest Tools Github
- Hacking Apps
- Nsa Hack Tools Download
- Hack Tools For Mac
- Pentest Tools Tcp Port Scanner
- Hacker Hardware Tools
- Hack Rom Tools
- Nsa Hack Tools Download
- Kik Hack Tools
- Hacking App
- Hack Tool Apk
- Hack Tools
- Hack Tools For Ubuntu
- Hacking Tools For Windows 7
- Usb Pentest Tools
- Hacker Tools Free Download
- Pentest Tools Review
- Hack And Tools
- Pentest Tools Kali Linux
- Hack Tools Pc
- Hack Tools 2019
- Hacking Tools Github
- Bluetooth Hacking Tools Kali
- Hacking Tools For Windows
- Underground Hacker Sites
- Blackhat Hacker Tools
- Hacking Tools Name
- Hacking Tools For Windows 7
- Hacker Tools For Windows
- Hacking Tools
- Wifi Hacker Tools For Windows
- Hacker Tools Free
- Growth Hacker Tools
- Hacking Tools For Beginners
- Hacking Tools Download
- Hacker Tool Kit
- Hacking Tools
- Nsa Hack Tools
- Hacker Tools List
- Hack Tools Github
- Pentest Tools Website Vulnerability
Comentarios
Publicar un comentario