Critical Bug Found In WordPress Plugin For Elementor With Over A Million Installations
A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Related articles
- Hack Tools For Pc
- Hack Tool Apk No Root
- Game Hacking
- Hacking Tools For Windows
- Hacking Tools For Windows 7
- Pentest Tools Github
- Hacker Security Tools
- Pentest Reporting Tools
- Hack Tools Download
- Hacking Tools For Windows Free Download
- Pentest Tools Find Subdomains
- Hacker Tools
- Hacking Tools 2019
- Hack Tools Mac
- Hacking Tools Name
- Pentest Tools Framework
- Best Hacking Tools 2019
- Wifi Hacker Tools For Windows
- Hacking Tools Usb
- Install Pentest Tools Ubuntu
- Hacker Search Tools
- How To Hack
- Top Pentest Tools
- Hacks And Tools
- World No 1 Hacker Software
- Pentest Tools List
- Usb Pentest Tools
- Best Pentesting Tools 2018
- Hacker Tools Apk Download
- Pentest Tools Port Scanner
- Hacking Tools Name
- Pentest Tools Port Scanner
- Pentest Tools Review
- Nsa Hack Tools Download
- Nsa Hack Tools
- Pentest Automation Tools
- Hack Rom Tools
- Hacker Tools Software
- Pentest Tools
- Hacker Tools 2020
- Hack And Tools
- Hacker Tools Free Download
- Hacking Tools For Windows
- Hacking Apps
- Wifi Hacker Tools For Windows
- Hacking Tools Usb
- Install Pentest Tools Ubuntu
- Pentest Tools For Android
- Pentest Tools Kali Linux
- Hacking Tools Pc
- Pentest Tools Url Fuzzer
- Hacking Tools For Windows 7
- New Hacker Tools
- How To Make Hacking Tools
- Pentest Tools Alternative
- Growth Hacker Tools
- Pentest Tools Open Source
- Pentest Tools Windows
- Hacking Tools Online
- Pentest Tools For Windows
- Hacker Tools Apk
- Usb Pentest Tools
- Pentest Tools Download
- Hacker Security Tools
- Hack And Tools
- Hacker Tools For Pc
- Pentest Tools Apk
- Hacks And Tools
- Hacker Tools Free Download
- How To Make Hacking Tools
- Hacking Tools For Games
- Hacking Tools For Pc
- New Hacker Tools
- How To Install Pentest Tools In Ubuntu
- Hack Apps
- Hacking Tools 2020
- Black Hat Hacker Tools
- Nsa Hack Tools
- How To Make Hacking Tools
- Pentest Tools Website Vulnerability
- What Is Hacking Tools
- Nsa Hacker Tools
- Pentest Tools
- Hack Tool Apk
- Physical Pentest Tools
- Nsa Hacker Tools
- Pentest Box Tools Download
- Black Hat Hacker Tools
- Wifi Hacker Tools For Windows
- Hack Tools For Games
- World No 1 Hacker Software
- Tools Used For Hacking
- Hackers Toolbox
- Hackers Toolbox
- Hacker Tools Mac
- Hack Tools For Games
- Hacking Tools For Kali Linux
- Underground Hacker Sites
- Hacking Tools For Games
- Hack Tools For Pc
- Hacking Tools For Pc
- Hacker Techniques Tools And Incident Handling
- Pentest Tools Nmap
- Hacker Tools Apk
- Nsa Hack Tools Download
- Bluetooth Hacking Tools Kali
- Hacking Tools And Software
- Hack App
- Nsa Hack Tools Download
- Pentest Tools Find Subdomains
- Pentest Tools Review
- Best Hacking Tools 2019
- New Hack Tools
- Hacking Tools For Windows
- Pentest Tools Apk
- Pentest Tools
- Hacker Tools 2020
- Hacking Tools For Windows
- Pentest Tools Github
- Hacking App
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Windows Free Download
- Pentest Tools Website Vulnerability
- Hack Tools 2019
0 Comments:
Post a Comment
<< Home