Security News > 2022 > December > Hackers exploit bug in WordPress gift card plugin with 50K installs

Hackers exploit bug in WordPress gift card plugin with 50K installs
2022-12-23 17:17

Hackers are actively targeting a critical flaw in YITH WooCommerce Gift Cards Premium, a WordPress plugin used on over 50,000 websites.

YITH WooCommerce Gift Cards Premium is a plugin that website operators to sell gift cards in their online stores.

Many sites still use the older, vulnerable version, and hackers have already devised a working exploit to attack them.

According to WordPress security experts at Wordfence, the exploitation effort is well underway, with hackers leveraging the vulnerability to upload backdoors on the sites, obtain remote code execution, and perform takeover attacks.

Wordfence reverse-engineered an exploit hackers are using in attacks, finding that the issue lies in the plugin's "Import actions from settings panel" function that runs on the "Admin init" hook.

The exploitation attempts are still ongoing, so users of the YITH WooCommerce Gift Cards Premium plugin are recommended to upgrade to version 3.21 as soon as possible.


News URL

https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159
Plugin 2 0 13 1 0 14