Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Independent Russian News Site Meduza Raises Over $200,000 in Crypto – Bitcoin News bitcoin news
  • the World’s Only DeFi Platform That Always Rewards, No Matter the Market – Sponsored Bitcoin News bitcoin news
  • Bitcoin Price Resumes Decline, Can The Bulls Save This Support bitcoin news
  • Do Knwon Turns Twitter Account To Private After LUNA Slumps bitcoin news
  • Crypto Custody Firm Fireblocks Launches Web3 Services Suite – Bitcoin News bitcoin news
  • Russia’s Industrial Giant Rostec Announces Blockchain-Based Alternative to SWIFT – Finance Bitcoin News bitcoin news
  • Ethereum Loses $1800 Handle – Will Bear Market Pull ETH Down Deeper? bitcoin news
  • Mykola Udianskyi Wins “Best Digital Currency Influencer 2022” at WIBA Awards in Cannes bitcoin news

Over a Million WordPress Sites Forcibly Updated to Patch a Critical Plugin Vulnerability

Posted on June 17, 2022 By root


WordPress

WordPress websites using a widely used plugin named Ninja Forms have been updated automatically to remediate a critical security vulnerability that’s suspected of having been actively exploited in the wild.

The issue, which relates to a case of code injection, is rated 9.8 out of 10 for severity and affects multiple versions starting from 3.0. It has been fixed in 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, and 3.6.11.

CyberSecurity

Ninja Forms is a customizable contact form builder that has over 1 million installations.

According to Wordfence, the bug “made it possible for unauthenticated attackers to call a limited number of methods in various Ninja Forms classes, including a method that unserialized user-supplied content, resulting in Object Injection.”

“This could allow attackers to execute arbitrary code or delete arbitrary files on sites where a separate [property oriented programming] chain was present,” Chloe Chamberland of Wordfence noted.

CyberSecurity

Successful exploitation of the flaw could allow an attacker to achieve remote code execution and completely take over a vulnerable WordPress site.

Users of Ninja Forms are advised to ensure that their WordPress sites are updated to run the latest patched version to prevent any possible exploitation attempts in the wild.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Anthony Scaramucci Reveals Buying Crypto During Crash, Suggests Staying Disciplined
Next Post: Colombian Financial Superintendence Prepares Norms for Crypto Transactions – Regulation Bitcoin News

Related Posts

  • Critical UNISOC Chip Vulnerability Affects Millions of Android Smartphones cyber security news
  • F5 Warns of a New Critical BIG-IP Remote Code Execution Vulnerability cyber security news
  • New Zimbra Email Vulnerability Could Let Attackers Steal Your Login Credentials cyber security news
  • U.S. Proposes $1 Million Fine on Colonial Pipeline for Safety Violations After Cyberattack cyber security news
  • Hackers Exploiting Unpatched Critical Atlassian Confluence Zero-Day Vulnerability cyber security news
  • Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • SEC Still Against Spot-based Bitcoin ETFs. Is There A Light At The End Of The Tunnel?
  • Demand for Hardware Crypto Wallets Increases Amid Currency Restrictions in Russia – Bitcoin News
  • Cumberland Says Financially Burdened Crypto Firms Are ‘Hanging Over the Market Like a Cloud’ – Bitcoin News
  • Worst Quarterly Bitcoin Crash In A Decade Closes Above Key Support
  • Bitmain Launches 2,400 Megahash E9 Ethereum Miner Ahead of The Merge – Mining Bitcoin News

Recent Comments

No comments to show.
  • Finance School Bentley University Now Accepts Cryptocurrency Payments for Tuition – Bitcoin News bitcoin news
  • What You Need to Know to Stay Resilient cyber security news
  • Bitcoin LTHs Realized Significant Losses Recently, Final Capitulation Here? bitcoin news
  • ExpressVPN Removes Servers in India After Refusing to Comply with Government Order cyber security news
  • Mars4 Metaverse is Selling Fast in Japan – Sponsored Bitcoin News bitcoin news
  • Asia Broadband’s Holdings Explode by 500% as the Company Continues Connecting the Dots Between Gold and Digital Assets bitcoin news
  • Bitcoin Recovers Above $30,000, Has The Bottom Been Marked? bitcoin news
  • Interpol Arrest Leader of SilverTerrier Cybercrime Gang Behind BEC Attacks cyber security news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme