Security News > 2020 > April > Flaw in defunct WordPress plugin exploited to create backdoor

Flaw in defunct WordPress plugin exploited to create backdoor
2020-04-29 11:27

A vulnerability discovered last year in the defunct OneTone WordPress theme plugin is now being exploited by hackers to compromise entire sites while installing backdoor admin accounts.

If successful, hijacking this session in turn allows them to create a backdoor admin account as well as set up additional PHP backdoors through the WordPress dashboard for added persistence.

Because the plugin seems to have stopped being updated in early 2018, and the company behind it hasn't replied to Sucuri's contacts, it seems reasonable to assume it will never be patched beyond its current version 1.1.1.

The issue of vulnerable plugins is now a perennial issue for WordPress sites which is why the platform's maintainers recently started testing a tool to manage this process automatically.

If the OneTone plugin is installed on your site, the best advice is simply to uninstall it as soon as you can.


News URL

https://nakedsecurity.sophos.com/2020/04/29/flaw-in-defunct-wordpress-plugin-exploited-to-create-backdoor/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159
Plugin 2 0 13 1 0 14