Front Page

Security Bulletin – Week of October 28th 2024

Welcome to this weekly’s security bulletin where we cover all the security vulnerabilities in the blogging sphere.

WordPress Plugin Vulnerabilities

Wordfence, the popular security service for WordPress websites, released their weekly report on found/known vulnerabilities in WordPress plugins. The list, some 221 plugins in all, is listed on their website.

WordPress websites effected with infostealers

Bleepingcomputer pushed an article about over 6,000 websites running on WordPress have been infected with hacked plugins pushing infostealers onto visitors.

According to the article, the known plugins effected are as follows:

LiteSpeed Cache ClassicCustom CSS Injector
MonsterInsights ClassicCustom Footer Generator
Wordfence Security ClassicCustom Login Styler
Search Rank EnhancerDynamic Sidebar Manager
SEO Booster ProEasy Themes Manager
Google SEO EnhancerForm Builder Pro
Rank Booster ProQuick Cache Cleaner
Admin Bar CustomizerResponsive Menu Builder
Advanced User ManagerSEO Optimizer Pro
Advanced Widget ManageSimple Post Enhancer
Content BlockerSocial Media Integrator

All these scam plugins seem to be related to real plugins with a similar name. GoDaddy posted a more in detailed description on hows these plugins work.

Published in: Security

This page has been accessed 26 times.

This page was last updated Mon Oct 28 22:50:52 2024 EDT

© 2020-2024 The Express Page
RSS | Mastodon | X | Bluesky