Security News > 2021 > December > Massive attack against 1.6 million WordPress sites underway

Massive attack against 1.6 million WordPress sites underway
2021-12-10 08:29

Wordfence analysts report having detected a massive wave of attacks in the last couple of days, originating from 16,000 IPs and targeting over 1.6 million WordPress sites.

The threat actors target four WordPress plugins and fifteen Epsilon Framework themes, one of which has no available patch.

Some of the targeted plugins were patched all the way back in 2018, while others had their vulnerabilities addressed as recently as this week.

"This makes it possible for attackers to register on any site as an administrator effectively taking over the site."

To check if your site has already been compromised, you can review all user accounts and look for any rogue additions that should be removed immediately.

In general, try to keep the number of plugins at your WordPress site to the absolute minimum necessary as this dramatically reduces the chances of being targeted and hacked in the first place.


News URL

https://www.bleepingcomputer.com/news/security/massive-attack-against-16-million-wordpress-sites-underway/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 93 44 18 157