Vietnam.vn - Nền tảng quảng bá Việt Nam

Security Flaw Puts 4 Million WordPress Websites at Risk

Báo Thanh niênBáo Thanh niên24/10/2023


Writing on its blog, the Wordfence threat intelligence team said it had responsibly disclosed a cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin, a popular add-on that is installed on more than 4 million WordPress websites. The vulnerability allowed hackers with contributor privileges to inject malicious scripts using shortcodes.

LiteSpeed Cache is a plugin that speeds up WordPress websites with caching and server-level optimization. This plugin provides a shortcode that can be used to cache blocks using Edge Side technology when added to WordPress.

However, Wordfence said the plugin’s implementation of the shortcode was insecure, allowing arbitrary scripts to be inserted into these pages. An examination of the vulnerable code revealed that the shortcode method did not adequately check inputs and outputs. This allowed the threat actor to perform XSS attacks. Once inserted into a page or post, the script would execute every time a user visited it.

Lỗi bảo mật khiến 4 triệu website WordPress gặp nguy hiểm - Ảnh 1.

LiteSpeed Cache is a famous speed-up plugin on WordPress platform.

While the vulnerability requires a compromised contributor account or a user to register as a contributor, Wordfence says an attacker could steal sensitive information, manipulate website content, attack administrators, edit files, or redirect visitors to malicious websites.

Wordfence said it contacted the LiteSpeed Cache development team on August 14. The patch was deployed on August 16 and released to WordPress on October 10. Users now need to update LiteSpeed Cache to version 5.7 to fully fix this security flaw. Although dangerous, the built-in Cross-Site Scripting protection feature of the Wordfence firewall helped prevent this exploit.



Source link

Comment (0)

No data
No data
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony
S-300PMU1 missiles on combat duty to protect Hanoi's sky
Lotus blooming season attracts tourists to the majestic mountains and rivers of Ninh Binh
Cu Lao Mai Nha: Where wildness, majesty and peace blend together

Heritage

Figure

Business

No videos available

News

Political System

Local

Product