Skip to content
WordPress

350,000 potentially attackable WordPress sites

Team Host.it 2 min read

Content

Hackers are actively exploiting a vulnerability that allows them to execute malicious commands and scripts on websites running File Manager, a WordPress plugin with over 700,000 active installations. News of the attacks came just hours after the security flaw was patched.

Hackers use the exploit to upload files that contain webshells hidden in an image. From there, they then have the option to run commands in plugins/wp-file-manager/lib/files/, the directory where the File Manager plugin resides. While this restriction prevents hackers from executing commands on files outside of the directory, hackers may be able to cause more damage by uploading scripts that can perform actions on other parts of a vulnerable site.

How to protect yourself from problems of this type? Obviously updating the software as soon as the patch is available, but it may not be enough. This is where having a WAF (web application firewall) to protect your WordPress site becomes essential. The "virtual patching" technology introduced by Cerbero (Host's web application firewall active on all services) guarantees the protection of WordPress websites even in the absence of a software update.

WordPress hosting

Hosting optimized for WordPress

SSD, backups, SSL and Application Manager: publish and update your site with Italian-speaking support.

From the blog

WordPress

WordPress 7.0 e l’AI

Cosa cambia per le web agency

Sicurezza

Patch a caldo, sito acceso

CVE kernel senza riavvii a raffica

From the archive

WordPress

Host Academy on the National Youth Card, 58% discount for young people up to 35 years old

WordPress

New features and releases - September 2022