Cyber Security

Zero-day in WPGateway WordPress plugin exploited in attacks

0

The Wordfence Threat Intelligence team warned that a zero-day flaw in the latest version of a WordPress premium plugin called WPGateway is being actively exploited in the wild, potentially allowing threat actors to completely take over affected sites.

WPGateway is a WordPress plugin that lets admins simplify various tasks such as setting up and backing up sites and managing themes and plugins from a central dashboard.

This critical privilege escalation security flaw tracked as CVE-2022-3180, enables unauthenticated attackers to add a malicious user with admin privileges to completely take over sites running the vulnerable WordPress plugin.

The Wordfence firewall has successfully blocked over 4.6 million attacks targeting this vulnerability against more than 280,000 sites in the past 30 days.

Wordfence has disclosed active exploitation of this security bug in the wild, but it did not release additional information regarding these attacks and details about the vulnerability.

If you want to check if your website was compromised in this ongoing campaign, you need to check for a new user with administrator permissions with the “rangex” username.

Additionally, requests to “//wp-content/plugins/wpgateway/wpgateway-webservice-new.php?wp_new_credentials=1” in the logs will show that your site was targeted in the attack but wasn’t necessarily compromised.

Those who have the WPGateway plugin installed are highly recommended to remove it immediately until a patch is made available and to check for malicious administrator users in the WordPress dashboard.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Cyber espionage group targets Asian Governments and Organizations

Previous article

Chinese hackers use new Linux version of the SideWalk Backdoor

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *