The Elementor Attacks: How Creative Hackers Combined Vulnerabilities to Take Over WordPress Sites

Поделиться
HTML-код
  • Опубликовано: 12 сен 2024
  • On May 6th (13 days ago), the Wordfence Threat Intelligence team alerted the WordPress community to vulnerabilities in Elementor Pro and Ultimate Addons for Elementor. At the time we did not release details of these vulnerabilities because the vendors had not had time to fix it. We made the urgent announcement withholding details because we were seeing an active attack campaign and sites being compromised.
    Today we can release full details of the attack campaign and associated vulnerabilities. Today’s report includes details on how attackers were using a combination of two vulnerabilities to compromise sites. Now that the vendors have released fixes and the community has had time to update, this video walkthrough of a site being exploited accompanies our blog post containing full disclosure of all technical details of these vulnerabilities and the associated attack campaign.

Комментарии • 24