Notification texts go here Contact Us Buy Now!

WordPress Vulnerable to Malicious Attacks!

WordPress Vulnerable to Malicious Attacks!

According to researchers at RIPS Technologies, a security analysis company, the core functions of WordPress execute a vulnerability, which may allow limited-privileged users and account hackers to not only run arbitrary/random code on the server, but also to delete important files. While it may sound trivial, these malicious acts can potentially lead to the entire website being hijacked. 

Although the researchers claim that they informed the management of the said domain a few weeks ago regarding the flaw, still no action has been taken against it, and the latest version of WordPress, i.e. 4.9.6, continues to be affected by it. 

The susceptibility lies in the “core deletion function” of the website, which accepts “unsanitized” user input. If interfered with, this could allow attackers to delete any file from the website, including the critical ones, like “.htaccess” and “wp-config.php” ones. The danger can somewhat be reduced by demanding an author account for deletion purposes, but this still cannot fully eliminate the issue. This is because the invader may get access to the credentials of the said account via phishing or other attacks. 

The problem arises when .htaccess files are erased. Holding security related configurations, their deletion would disable protection from the site. Moreover, the removal of wp-config.php would force the website back to the installation screen, enabling the hacker to reconfigure the browser, update credentials (since he/she cannot directly read from the concerned file), shutting the admin out. With this, he/she would have complete, unhindered access to the site. 

But for now, users need to not worry. The researchers also presented hotfix, which manually rectifies the problem. However, it is time that WordPress actually looks into this issue, and ensures that the upcoming versions are not affected by this flaw.



About the Author

A tech blog focused on blogging tips, SEO, social media, mobile gadgets, pc tips, how-to guides and general tips and tricks

Post a Comment

Oops!
It seems there is something wrong with your internet connection. Please connect to the internet and start browsing again.
AdBlock Detected!
We have detected that you are using adblocking plugin in your browser.
The revenue we earn by the advertisements is used to manage this website, we request you to whitelist our website in your adblocking plugin.
Site is Blocked
Sorry! This site is not available in your country.