A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Related news
- Hacker Tools For Windows
- Hack Tool Apk No Root
- Hacker Tools List
- Hacking Tools For Games
- Hack Tools For Mac
- Hacker
- Hack Rom Tools
- Hacker Search Tools
- Hacker Tools Online
- Hacker Tool Kit
- How To Hack
- New Hacker Tools
- Pentest Automation Tools
- Github Hacking Tools
- Hacking Tools Usb
- Hack Tools For Pc
- Hack Tools Pc
- Hack Website Online Tool
- Pentest Tools
- Pentest Box Tools Download
- Hacking App
- Hacking Tools Free Download
- How To Install Pentest Tools In Ubuntu
- Hacker Tools Free
- Hacking Tools For Kali Linux
- New Hack Tools
- Hacker
- Hacker Security Tools
- Underground Hacker Sites
- Blackhat Hacker Tools
- Hacking App
- World No 1 Hacker Software
- Pentest Reporting Tools
- Pentest Tools For Ubuntu
- Hacker Tools Apk Download
- Hacking Tools Windows 10
- Hak5 Tools
- Hacker Tools For Pc
- Hacking Tools For Kali Linux
- Hacker Tools Apk Download
- Pentest Tools Download
- New Hack Tools
- Pentest Tools List
- Pentest Tools Website
- Hacking Tools Download
- Pentest Tools Bluekeep
- Hacking Tools Online
- What Are Hacking Tools
- Hacker Tools Hardware
- Pentest Tools Android
- Pentest Tools Bluekeep
- Hacker Security Tools
- Hacking Tools For Windows Free Download
- Hack Tools 2019
- Pentest Tools Windows
- Hack Tools For Mac
- Hack Tools Online
- Hack Tools
- Hacking Tools Online
- What Are Hacking Tools
- Hack Tools For Windows
- Best Pentesting Tools 2018
- New Hack Tools
- Hack Rom Tools
- Hacker Tools 2019
- Hacker Tools For Ios
- Pentest Tools For Ubuntu
- Nsa Hacker Tools
- Game Hacking
- Hacking Tools
- Hack Tools Online
- Tools 4 Hack
- Pentest Tools Nmap
- Pentest Tools Android
- Github Hacking Tools
- How To Install Pentest Tools In Ubuntu
- Hack Rom Tools
- Hacking Tools For Windows 7
- Hacker Tools 2020
- Hacker Tools Free Download
- Hacker Hardware Tools
- World No 1 Hacker Software
- Hacking Tools
- Pentest Box Tools Download
- Pentest Tools Framework
- Usb Pentest Tools
- Pentest Tools Kali Linux
- Underground Hacker Sites
- Hack App
- Tools 4 Hack
- Hack Tools For Ubuntu
- Wifi Hacker Tools For Windows
- Hacker Search Tools
- Pentest Box Tools Download
- What Is Hacking Tools
- Underground Hacker Sites
- Pentest Tools Free
- Hacking Tools Hardware
- Pentest Automation Tools
- Wifi Hacker Tools For Windows
- Hacking Tools And Software
- Hacking Tools Pc
- Hacking Tools 2020
- Hack Tools For Ubuntu
- Android Hack Tools Github
- Pentest Recon Tools
- Hacking Tools For Pc
- Termux Hacking Tools 2019
- Hacking Tools Name
- Pentest Tools Find Subdomains
- Hacking Tools
- Hacking Tools Pc
- Pentest Tools Free
- Hacker Tools For Pc
- Hacking Tools For Mac
- Hacker Tools Apk Download
- Hacker Techniques Tools And Incident Handling
- Hacker Tools For Pc
- Blackhat Hacker Tools
- Pentest Tools For Ubuntu
- Tools Used For Hacking
- Pentest Tools Android
- Hack Tools For Pc
- Hacker Tools Windows
- Termux Hacking Tools 2019
- Tools 4 Hack
- Hacking Tools Name
- Pentest Tools Windows
- Hack Tool Apk No Root
- Hacking App
- Pentest Tools Nmap
- Hacking Tools Download
- Usb Pentest Tools
- Hacking Tools Kit
- Bluetooth Hacking Tools Kali
- Hacking Tools Online
- Pentest Tools List
- Hack Tool Apk No Root
- Hacker Tools For Ios
- Hacking Tools For Windows Free Download
- Pentest Tools Online
- Hacker Tools For Mac
- Hacking Tools Windows
- Game Hacking
- Hacker Security Tools
- Pentest Tools
- Hack App
- Hacking Tools Github
- Pentest Tools Download
- Hacker Tools For Pc
- Hack Tools For Mac
- Pentest Tools Nmap
- Hacking Tools And Software
- Underground Hacker Sites
- Nsa Hacker Tools
- Pentest Tools For Ubuntu
- Beginner Hacker Tools
- Hack Tools
- Pentest Tools Online
- Kik Hack Tools
- Hacking Tools Github
- Hacking Tools Usb
- Pentest Tools List
- Hacker Tools Windows
- Tools For Hacker
- Pentest Tools Website
0 comments
Post a Comment