Security News > 2021 > December > 1.6 Million WordPress Sites Under Cyberattack From Over 16,000 IP Addresses

1.6 Million WordPress Sites Under Cyberattack From Over 16,000 IP Addresses
2021-12-10 19:50

As many as 1.6 million WordPress sites have been targeted by an active large-scale attack campaign originating from 16,000 IP addresses by exploiting weaknesses in four plugins and 15 Epsilon Framework themes.

WordPress security company Wordfence, which disclosed details of the attacks, said Thursday it had detected and blocked more than 13.7 million attacks aimed at the plugins and themes in a period of 36 hours with the goal of taking over the websites and carrying out malicious actions.

The plugins in question are Kiwi Social Share, WordPress Automatic, Pinterest Automatic, and PublishPress Capabilities, some of which have been patched dating all the way back to November 2018.

Most of the attacks observed by Wordfence involve the adversary updating the "Users can register" option to enabled and setting the "Default role" setting to administrator, thereby allowing an adversary to register on the vulnerable sites as an administrator and seize control.

What's more, the intrusions are said to have spiked only after December 8, indicating that "The recently patched vulnerability in PublishPress Capabilities may have sparked attackers to target various Arbitrary Options Update vulnerabilities as part of a massive campaign," Wordfence's Chloe Chamberland said.

In light of active exploitation, WordPress site owners running any of the aforementioned plugins or themes are recommended to apply the latest fixes to mitigate the threat.


News URL

https://thehackernews.com/2021/12/16-million-wordpress-sites-under.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 49 36 410 104 29 579