Thousands of WordPress websites at risk thanks to an obscure flaw null


Security researchers have discovered that hackers are actively exploiting a vulnerability in the WordPress plugin File Manager which could allow them to execute commands and malicious scripts on websites that have not yet updated to the latest version of the plugin.
As reported by Ars Technica, attackers are leveraging the exploit to upload files containing webshells hidden in images. From there, they can run commands in the directory where the File Manager plugin resides on vulnerable WordPress sites.
File Manager is a popular plugin and it is currently installed on over 700,000 websites. According to the website security firm Wordfence, it has blocked over 450,000 exploit attempts in the past few days where attackers tried to inject various files with names such as hardfork.php, hardfind.php and x.php.
In a blog post, threat analyst at Wordfence Chloe Chamberland explained how attackers could gain privilege escalation by exploiting the vulnerability in the File Manager plugin, saying:
“A file manager plugin like this would make it possible for an attacker to manipulate or upload any files of their choosing directly from the WordPress dashboard, potentially allowing them to escalate privileges once in the site’s admin area. For example, an attacker could gain access to the admin area of the site using a compromised password, then access this plugin and upload a webshell to do further enumeration of the server and potentially escalate their attack using another exploit. For this reason, we recommend uninstalling utility plugins, like file management plugins, when they are not in use, so that they do not create an easy intrusion vector for attackers to escalate their privileges.”
File Manager plugin
The File Manager plugin helps administrators manage files on sites running WordPress and it also contains an additional file manager known as elFinder which is an open source library that provides the plugin’s core functionality. However, the vulnerability that is now being exploited by attackers online occurred as a result of the way the plugin’s developers implemented elFinder.
Systems Team Lead at Seravo, Ville Korhonen was the first person to discover and report the vulnerability to File Manager’s developers.
The security flaw is present in File Manager versions 6.0 to 6.8 but thankfully its developers recently released version 6.9 of the plugin which addresses the vulnerability.
WordPress site owners that use File Manager should update the plugin to version 6.9 immediately to avoid falling victim to any potential attacks that exploit the now patched vulnerability.
Via Ars Technica
Security researchers have discovered that hackers are actively exploiting a vulnerability in the WordPress plugin File Manager which could allow them to execute commands and malicious scripts on websites that have not yet updated to the latest version of the plugin. As reported by Ars Technica, attackers are leveraging the…
Recent Posts
- An obscure French startup just launched the cheapest true 5K monitor in the world right now and I can’t wait to test it
- Google Meet’s AI transcripts will automatically create action items for you
- No, it’s not an April fool, Intel debuts open source AI offering that gauges a text’s politeness level
- It’s clearly time: all the news about the transparent tech renaissance
- Windows 11 24H2 hasn’t raised the bar for the operating system’s CPU requirements, Microsoft clarifies
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010