Critical Bug Found In WordPress Plugin For Elementor With Over A Million Installations

 


A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.

The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.

"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."

That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.

The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."

The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.

Continue reading
  1. Hack Website Online Tool
  2. Black Hat Hacker Tools
  3. Pentest Tools Framework
  4. Pentest Tools For Windows
  5. Pentest Reporting Tools
  6. Hack Rom Tools
  7. Hacks And Tools
  8. Hacker Hardware Tools
  9. Growth Hacker Tools
  10. Hacker Tools List
  11. Pentest Tools Alternative
  12. Hacking Tools 2019
  13. Best Hacking Tools 2019
  14. Hacker Tools Mac
  15. Hack And Tools
  16. Pentest Tools Tcp Port Scanner
  17. Hack Apps
  18. Usb Pentest Tools
  19. Hack Tools Github
  20. Pentest Tools For Ubuntu
  21. Hacking Tools Windows 10
  22. Hack Tools Github
  23. Tools For Hacker
  24. Pentest Tools Windows
  25. Hacker Tools Hardware
  26. Hacker Tools 2020
  27. Pentest Reporting Tools
  28. Hack Rom Tools
  29. Pentest Tools Linux
  30. Pentest Recon Tools
  31. Hacking Tools And Software
  32. Best Pentesting Tools 2018
  33. Hacks And Tools
  34. Pentest Tools Github
  35. Hacker Tools Linux
  36. Pentest Tools Website
  37. Tools For Hacker
  38. Hacker Tools Free Download
  39. Best Pentesting Tools 2018
  40. Pentest Tools Alternative
  41. Hacking Tools Usb
  42. Pentest Tools Website
  43. Tools For Hacker
  44. Hacking Tools
  45. Hackrf Tools
  46. Hacker Tools 2019
  47. Pentest Tools Website Vulnerability
  48. Hacking Tools 2020
  49. Hacking Tools For Beginners
  50. Hack Tool Apk No Root
  51. What Is Hacking Tools
  52. Pentest Tools Online
  53. Hack Tools Github
  54. Hak5 Tools
  55. Hacker Tools Linux
  56. Hacker Tool Kit
  57. Hack Tools Mac
  58. Hacking Tools Software
  59. Hacking Tools Online
  60. Nsa Hack Tools
  61. Pentest Tools Find Subdomains
  62. Hacking App
  63. Hack Tools For Windows
  64. Blackhat Hacker Tools
  65. Hacker
  66. Hacker Tools Apk
  67. Hacker Tools For Windows
  68. Hacking Tools Windows
  69. Hacking Tools For Pc
  70. Hack Tool Apk No Root
  71. Physical Pentest Tools
  72. Nsa Hack Tools Download
  73. Hacker Tools Online
  74. Underground Hacker Sites
  75. Hacker Tools Software
  76. Hacker Tools Apk
  77. Pentest Tools For Ubuntu
  78. Hacker Tools Apk
  79. Hacking Tools Mac
  80. Tools 4 Hack
  81. Hak5 Tools
  82. How To Install Pentest Tools In Ubuntu
  83. Pentest Tools Tcp Port Scanner
  84. Hacking Tools For Windows Free Download
  85. Tools For Hacker
  86. Easy Hack Tools
  87. Pentest Tools Tcp Port Scanner
  88. Hacker Tools For Windows
  89. Hacker Tool Kit
  90. Hacking Tools Github
  91. Pentest Tools For Windows
  92. Hacker Tools For Pc
  93. Pentest Reporting Tools
  94. Pentest Recon Tools
  95. Best Hacking Tools 2019
  96. Pentest Tools Website
  97. Hacker Search Tools
  98. New Hacker Tools
  99. Pentest Tools Subdomain
  100. Hacker Tool Kit
  101. Hack Website Online Tool
  102. Pentest Reporting Tools
  103. World No 1 Hacker Software
  104. Hack Tool Apk

No hay comentarios:

Publicar un comentario