A new WordPress plugin vulnerability is now putting millions of users at risk. This security issue is specifically found on UpdraftPlus, a cloning plugin for WordPress.
This online tool allows users to send an installed link to their backup via email. Many people are currently relying on UpdraftPlus since it is quite easy to use and offers many advanced features.
But, there's an issue with this clone WP plugin. Some security experts claimed that the main feature of UpdraftPlus is implemented in a poor manner.
Because of this, a new vulnerability appeared, which can put millions of WordPress users at risk.
New WordPress Plugin Flaw
According to TechRadar's latest report, the new UpdraftPlus vulnerability allows anyone, even sub-level subscribers, to create a valid link. This will allow them to acquire backup files.
Also Read : New WordPress Cyberattack Affects 1.6 Million Websites! Wordfence Says 13.7 Million Attacks Were Prevented
Wordfence, the threat intelligence agency, confirmed that the new flaw can allow anyone to access sensitive user data of UpdraftPlus users.
"The attack starts with the WordPress heartbeat function. The attacker needs to send a specially crafted heartbeat request containing a data[updraftplus] parameter," explained Wordfence experts via ZDNet.
Although the new flaw is quite serious, involved cybersecurity researchers said that users can still prevent the vulnerability from exploiting their passwords, identity information, and other sensitive data.
Update Your WP plugin Now
Wordfence is now urging UpdraftPlus users to update their plugins as soon as possible.
Security experts said this is a must since the new vulnerability can lead to massive breaches, especially if the attackers acquire database credentials from a configuration file.
They added that credential theft is most likely the first priority of cybercriminals if ever they gain access to the backups and database of UpdraftPlus.
In other news, some WordPress plugin flaws also put millions of websites at risk of cyberattacks. Meanwhile, Glow software company recently released an all-in-one WordPress site management tool.
For more news updates about WordPress and other related topics, always keep your tabs open here at TechTimes.
Related Article : Outdated WordPress Plug-ins, Themes Distribute Backdoors For Potential Supply Chain Attack, Jetpack Says
This article is owned by TechTimes
Written by: Griffin Davis