WordPress plugins with more than 300,000 pages that use vulnerabilities are vulnerable to SQL Injection attacks
This error is found on the popular WP Statistics plugin, which allows site administrators to get detailed information regarding the number of online users on the page, visits, visitors and site statistics.
Discovered by the Sucuri team, the WP Statistics plugin is vulnerable to SQL Injection attacks, which allows remote attackers, with only one registered account, to steal sensitive information from the database. data of the website and may occupy website access.
SQL Injection is a web application error, allowing a hacker to inject SQL (Structured Query Language) code into web input data to determine the structure and location of the key database, ultimately allowing stealing information from there.
SQL Injection vulnerability may lie on many functions, including wp_statistics_searchengine_query ()
'This vulnerability is due to lack of control over the data that users provide. Some properties of shortcode wpstatistics have been omitted instead of being recognized as parameters for important functions, 'the researchers said. 'One of the vulnerable functions is the search query wp_statistics_searchengine_query () in includes / functions / functions.php file, accessed via AJAX of WordPress thanks to wp_ajax_parse_media_shortcode ().'
This function does not check for additional privileges, which allows website followers to execute shortcode and inject malicious code into properties. Researchers at Sucuri reported this error to the WP Statistics team and the group patched this vulnerability in the latest version 12.0.8. So if you are using a version with a vulnerability and your website allows users to register, quickly install the latest version.
You should read it
- Which platform is better for WordPress.com and WordPress.org?
- Critical Vulnerability Discovered in 3 WordPress Plugins, Affects 84,000 Websites
- 5 mistakes everyone mistakenly thinks about WordPress
- What's new in WordPress 5.4?
- Instructions for creating web pages in Wordpress from A to Z (Part 2)
- 5 best e-commerce WordPress plugins
- 30 best free WordPress presentation plugins (2018)
- How to add new posts on WordPress
May be interested
- The Linux machine can be remotely hacked with a poisoned DNS responsean important vulnerability was discovered on systemd, the init system and managed on a linux machine, allowing the hacker to cause a buffer overflow to execute malicious code on the target machine via dns feedback.
- How to hack Gmail's two-step authenticationtwo-factor authentication does not mean that you are absolutely safe against phishing attackers.
- Samsung Flow can be used on Windows 10 computersinterested users have also heard that samsung is updating the samsung flow application so everyone can use it on windows 10 pc.
- Research shows that just getting a smartphone close by can make you 'more foolish'.a recent study shows that just getting a smartphone close to you makes you more foolish. invite you to learn the reason behind it!
- The researchers successfully cracked 1024-bit RSA in GnuPG Crypto Librarysecurity researchers have discovered an important flaw in the gnupg cryptographic library that completely disables 1024-bit rsa and successfully retrieves the rsa secret key to decrypt the data.
- Why will AirPods finally be available in the iPhone box?what if in the future, the apple product is completely wireless, and you still use headphopne with a 3.5mm jack?