{"id":1453,"date":"2020-02-26T14:20:09","date_gmt":"2020-02-26T10:20:09","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1453"},"modified":"2025-04-16T15:43:42","modified_gmt":"2025-04-16T11:43:42","slug":"200000-wordpress-sites-risk-of-attack","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/200000-wordpress-sites-risk-of-attack\/","title":{"rendered":"Plugin flaw leaves up to 200,000 WordPress sites at risk of attack"},"content":{"rendered":"\n<p><strong>By Tomas Foltyn, security\nwriter at ESET<\/strong><\/p>\n\n\n\n<p>A popular WordPress theme plugin that\u2019s\ninstalled on some 200,000 websites has been found to contain a serious\nvulnerability that, if abused, could allow remote attackers to wipe the sites\nand gain admin access to them.<\/p>\n\n\n\n<p>Discovered by\u00a0<a href=\"https:\/\/www.webarxsecurity.com\/critical-issue-in-themegrill-demo-importer\/\" target=\"_blank\" rel=\"noreferrer noopener\">website security outfit WebARX<\/a>, the <a href=\"https:\/\/techxmedia.com\/tag\/security\/\">security<\/a> flaw affects the\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/themegrill-demo-importer\/\" target=\"_blank\" rel=\"noreferrer noopener\">ThemeGrill Demo Importer<\/a>\u00a0plugin, which comes installed with site themes designed by web development company ThemeGrill. WordPress website admins can use the plugin to import demo content, widgets and settings and easily customize their site\u2019s theme.<\/p>\n\n\n\n<p>For three years, however, the plugin\nsuffered from a security hole that left the sites open to remote attacks. In\nversions 1.3.4 up to 1.6.1, \u201cthere is a vulnerability that allows any\nunauthenticated user to wipe the entire database to its default state after\nwhich they are automatically logged in as an administrator,\u201d reads the report.<\/p>\n\n\n\n<p>\u201cIn order to be automatically logged in as\nan administrator, there must be a user called \u2018admin\u2019 in the database.\nRegardless of this condition, the database will still be wiped to its default\nstate,\u201d said the researchers. The exploit only works if the plugin is\nactivated.<\/p>\n\n\n\n<p>Either way, the firm stressed that the\nexploit doesn\u2019t require any suspicious-looking payload \u2013 similar to the exploit\nabusing a critical vulnerability in the&nbsp;<a href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\" target=\"_blank\" rel=\"noreferrer noopener\">InfiniteWP Client and WP Time\nCapsule plugins<\/a>&nbsp;that was\ndisclosed Six weeks ago.<\/p>\n\n\n\n<p>WebARX said that it discovered and\nreported the latest security hole to the tool\u2019s developer on February 6. The\nfix was eventually supplied with the plugin\u2019s version 1.6.2 on February 15. As\na result, users are advised to ensure that they run either this version or\nversion 1.6.3, which was rolled out earlier.<\/p>\n\n\n\n<p><strong>WordPress in\nattackers\u2019 crosshairs<\/strong><\/p>\n\n\n\n<p>WordPress security should be high on the\nagenda of any website owner using the web publishing software.&nbsp;<a href=\"https:\/\/w3techs.com\/technologies\/details\/cm-wordpress\" target=\"_blank\" rel=\"noreferrer noopener\">According to W3Techs<\/a>, WordPress powers more than 35 percent of all websites, and its\npopularity is partly thanks to thousands of available official plugins that\nextend the sites\u2019 functionalities.<\/p>\n\n\n\n<p>On the other hand, the platform\u2019s success\ncan also turn all those sites into juicy targets for cybercriminals, and\nout-of-date plugins and themes often&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2018\/11\/13\/attackers-exploit-flaw-gdpr-themed-wordpress-plugin\/\" target=\"_blank\" rel=\"noreferrer noopener\">increase the attack surface<\/a>&nbsp;of WordPress installations. Besides updating the core software, then,\nthe importance of also keeping plugins up-to-date and ditching abandoned and\nno-longer-needed plugins cannot be overstated.<\/p>\n\n\n\n<p>In addition, since many hacks&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2017\/04\/06\/sathurbot-distributed-wordpress-password-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">originate from compromised login\ncredentials<\/a>, make sure your password or&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/05\/forget-about-passwords-you-need-a-passphrase\/\" target=\"_blank\" rel=\"noreferrer noopener\">passphrase<\/a>&nbsp;is&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/01\/08\/new-years-resolutions-passwords-shipshape\/\" target=\"_blank\" rel=\"noreferrer noopener\">strong and unique<\/a>&nbsp;and that, wherever available, you&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">use two-factor authentication<\/a>&nbsp;for extra security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A popular WordPress theme plugin that\u2019s installed on some 200,000 websites has been found to contain a serious vulnerability that, if abused, could allow remote attackers to wipe the sites and gain admin access to them.<\/p>\n","protected":false},"author":8,"featured_media":1455,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[9618],"tags":[518,527,573,582,583,584,581],"contributor":[],"class_list":["post-1453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-pick","tag-cyber_security","tag-cyber_threat","tag-eset","tag-plugin","tag-web_security","tag-webarx","tag-wordpress"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/02\/Tomas-Foltyn-security-writer-at-ESET-e1582712312193.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1453"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1453\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1455"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1453"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}