350,000 potentially attackable WordPress sites
Team Host.it 2 min read
Content
Hackers are actively exploiting a vulnerability that allows them to execute malicious commands and scripts on websites running File Manager, a WordPress plugin with over 700,000 active installations. News of the attacks came just hours after the security flaw was patched.
Hackers use the exploit to upload files that contain webshells hidden in an image. From there, they then have the option to run commands in plugins/wp-file-manager/lib/files/, the directory where the File Manager plugin resides. While this restriction prevents hackers from executing commands on files outside of the directory, hackers may be able to cause more damage by uploading scripts that can perform actions on other parts of a vulnerable site.
How to protect yourself from problems of this type? Obviously updating the software as soon as the patch is available, but it may not be enough. This is where having a WAF (web application firewall) to protect your WordPress site becomes essential. The "virtual patching" technology introduced by Cerbero (Host's web application firewall active on all services) guarantees the protection of WordPress websites even in the absence of a software update.
WordPress hosting
Hosting optimized for WordPress
SSD, backups, SSL and Application Manager: publish and update your site with Italian-speaking support.
Related articles
From the blog
From the archive