Security News > 2021 > June > Actively Exploited Zero-Day Found in Popular WordPress eCommerce Plugin

Actively Exploited Zero-Day Found in Popular WordPress eCommerce Plugin
2021-06-02 15:02

More than 17,000 websites are exposed to attacks targeting a critical zero-day vulnerability in the Fancy Product Designer WordPress plugin, the Wordfence team at WordPress security company Defiant warns.

Fancy Product Designer is a premium plugin for online stores that provides users with the ability to customize products with images and PDF files uploaded from various devices.

The plugin provides various other customization options as well.

The issue, they explain, could be exploited in certain configurations even if the plugin has been deactivated.

An attacker targeting the vulnerability could upload executable PHP files to any website that has the plugin installed.

The developer of Fancy Product Designer was informed about the vulnerability on May 31, the day the Wordfence team noticed the attacks.


News URL

http://feedproxy.google.com/~r/securityweek/~3/L2TYw_bdO74/actively-exploited-zero-day-found-wordpress-plugin-used-many-online-stores

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 93 44 18 157
Plugin 2 0 13 1 0 14