Skip to main content

Posts

Showing posts from February, 2020

Site Takeover Campaign Exploits Multiple Zero-Day Vulnerabilities

This entry was posted in  Vulnerabilities ,  WordPress Security  on February 27, 2020 by  Mikey Veenstra     0 Replies Early yesterday, the  Flexible Checkout Fields for WooCommerce  plugin received a critical update to patch a zero-day vulnerability which allowed attackers to modify the plugin’s settings. As our Threat Intelligence team researched the scope of this attack campaign, we discovered  three additional zero-day vulnerabilities  in popular WordPress plugins that are being exploited as a part of this campaign. The targeted plugins were  Async JavaScript ,  Modern Events Calendar Lite , and  10Web Map Builder for Google Maps . At this time, we have reached out to each plugin’s development team in hopes of getting these issues resolved quickly. This attack campaign exploits XSS vulnerabilities in the above plugins to inject malicious Javascript that can create rogue WordPress administrators and install malicious plugins that include backdoors. It is important that site admini