A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
Read more
- Hacking Tools Name
- Hacking Tools For Games
- Pentest Tools Tcp Port Scanner
- Pentest Tools Alternative
- Hack Tool Apk No Root
- Hacking Tools For Windows 7
- Hacker Tools Github
- Hacker Tools Apk Download
- Growth Hacker Tools
- Hacker Search Tools
- Hacker Tools For Pc
- Usb Pentest Tools
- Pentest Tools Open Source
- Top Pentest Tools
- Hacker Tools Github
- Hacker Tools Free Download
- Hacking Tools Name
- Computer Hacker
- Beginner Hacker Tools
- Hacking Tools For Windows 7
- Pentest Tools Port Scanner
- Pentest Tools Github
- Hacker Tools Apk Download
- Growth Hacker Tools
- Hacking Tools Name
- Hacking Tools Online
- Github Hacking Tools
- Hacker Tools Github
- Hacking Apps
- Pentest Tools For Mac
- Hacking Apps
- Hacking Tools
- Hacking Tools
- Hacking Tools For Mac
- Hack Tools For Ubuntu
- Hack Tool Apk
- Hack Apps
- Pentest Reporting Tools
- Hack And Tools
- Hacking Tools Usb
- Best Hacking Tools 2019
- Hack Tool Apk No Root
- Pentest Tools Apk
- Hacking Tools Github
- Pentest Tools Android
- Black Hat Hacker Tools
- Pentest Automation Tools
- Hacking Tools Hardware
- Hak5 Tools
- Pentest Tools Apk
- Pentest Tools For Windows
- Hacker Tools Github
- Pentest Tools Github
- Hack Tool Apk
- Bluetooth Hacking Tools Kali
- Wifi Hacker Tools For Windows
- Hacker
- Hacking Tools For Windows Free Download
- Hacker Tools Apk
- Pentest Tools Nmap
- Hack Tools For Mac
- Pentest Tools Framework
- Pentest Tools Alternative
- Hack Tools Github
- Hack Rom Tools
- Hack Rom Tools
- Hacking Tools Pc
- Hack Tool Apk
- Hack Tools
- Ethical Hacker Tools
- New Hack Tools
- Hacking Tools Hardware
- Hacking Tools For Beginners
- Hacker Tools Windows
- Hack Tool Apk No Root
- Pentest Tools Port Scanner
- Easy Hack Tools
- Hacking Tools Name
- Pentest Tools Tcp Port Scanner
- Pentest Tools Open Source
- Best Hacking Tools 2020
- Hacker Tools Apk Download
- Hack Website Online Tool
- Pentest Tools Review
- Hacking Tools
- Best Hacking Tools 2019
- Hacker Tools Free Download
- Blackhat Hacker Tools
- World No 1 Hacker Software
- Hacker Tools Apk Download
- How To Install Pentest Tools In Ubuntu
- Pentest Tools For Ubuntu
- Pentest Tools Review
- Hack Tools Download
- Hack Tools For Ubuntu
- Pentest Tools Apk
- Tools Used For Hacking
- Hack Tools For Pc
- Hack App
- What Are Hacking Tools
- Hack Apps
- Hacker Tools Free
- Pentest Tools Tcp Port Scanner
- Hacking Tools Mac
- Hacking Tools For Kali Linux
- Hacking Tools For Pc
- Hacking Tools For Windows Free Download
- Hacker Tools Software
- Pentest Tools For Ubuntu
- Hacking Tools Github
- Black Hat Hacker Tools
- Best Hacking Tools 2020
- Blackhat Hacker Tools
- Github Hacking Tools