Vulnerabilities

WordPress Automatic plugin triggers millions of SQL injection attacks

0

Hackers are targeting a critical severity vulnerability in the WP Automatic plugin for WordPress to create user accounts with administrative privileges and to plant backdoors for long-term access.

The plugin, which has been installed on more than 30,000 websites, lets administrators automate content importing (e.g. text, images, video) from various online sources and publishing on their WordPress site.

The exploited vulnerability is tracked as CVE-2024-27956 and has a severity score of 9.9/10.

The researchers at PatchStack vulnerability mitigation service has publicly disclosed the vulnerability on March 13 and described as an SQL injection issue that impacts affecting WP Automatic versions before 3.9.2.0.

The issue is in the plugin’s user authentication mechanism, which can be bypassed to submit SQL queries to the site’s database. Hackers can use specially crafted queries to create administrator accounts on the target website.

Since PatchStack disclosed the security issue, Automatic’s WPScan observed more than 5.5 million attacks trying to leverage the vulnerability, most of them being recorded on March 31st.

WPScan reports that after obtaining admin access to the target website, attackers create backdoors and obfuscate the code to make it more difficult to find.

To prevent other hackers from compromising the website by exploiting the same issue and to avoid detection, the hackers also rename the vulnerable file “csv.php.”

After getting control of the website, the threat actor often installs additional plugins that allow uploading files and code editing.

WPScan provides a set of indicators of compromise that can help admins determine if their website was hacked.

Administrators can check for signs whether hackers took over the website by looking for the presence of an admin account starting with “xtw” and files named web.php and index.php, which are the backdoors planted in the recent campaign.

To mitigate the risk of being breached, researchers recommend WordPress site administrators to update the WP Automatic plugin to version 3.9.2.1 or later.

The website owners are also recommended to frequently create backups of their site so they can install clean copies quickly in case of a compromise.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

US takes down illegal Cryptocurrency Mixing Service Samourai Wallet

Previous article

Cuttlefish malware targets enterprise-grade SOHO routers

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *