Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • 1940s railroad car becomes unique tiny house
    • Berlin’s Emerge Tech nabs funding to bring AI-powered employer branding to SMEs — no agency needed
    • 12 Ways to Upgrade Your Wi-Fi and Make Your Internet Faster (2025)
    • VMware perpetual license holders receive cease-and-desist letters from Broadcom
    • Apple iPhone 16E Specs vs. iPhone 15 Pro: New Entry-Level or Last Year’s Pro
    • The US factory that lays bare the contradiction in Trump’s policy
    • The Automation Trap: Why Low-Code AI Models Fail When You Scale
    • Inside the story that enraged OpenAI
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Monday, May 19
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Critical WordPress plugin vulnerability under active exploit threatens thousands
    News

    Critical WordPress plugin vulnerability under active exploit threatens thousands

    Editor Times FeaturedBy Editor Times FeaturedDecember 18, 2024No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    1000’s of websites operating WordPress stay unpatched in opposition to a essential safety flaw in a extensively used plugin that was being actively exploited in assaults that permit for unauthenticated execution of malicious code, safety researchers stated.

    The vulnerability, tracked as CVE-2024-11972, is present in Hunk Companion, a plugin that runs on 10,000 websites that use the WordPress content material administration system. The vulnerability, which carries a severity ranking of 9.8 out of a potential 10, was patched earlier this week. On the time this publish went stay on Ars, figures offered on the Hunk Companion web page indicated that lower than 12 % of customers had put in the patch, that means practically 9,000 websites could possibly be subsequent to be focused.

    Important, multifaceted risk

    “This vulnerability represents a big and multifaceted risk, concentrating on websites that use each a ThemeHunk theme and the Hunk Companion plugin,” Daniel Rodriguez, a researcher with WordPress safety agency WP Scan, wrote. “With over 10,000 energetic installations, this uncovered hundreds of internet sites to nameless, unauthenticated assaults able to severely compromising their integrity.”

    Rodriquez stated WP Scan found the vulnerability whereas analyzing the compromise of a buyer’s website. The agency discovered that the preliminary vector was CVE-2024-11972. The exploit allowed the hackers behind the assault to trigger susceptible websites to routinely navigate to wordpress.org and obtain WP Query Console, a plugin that hasn’t been up to date in years.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    VMware perpetual license holders receive cease-and-desist letters from Broadcom

    May 19, 2025

    WhatsApp provides no cryptographic management for group messages

    May 19, 2025

    Trump admin to roll back Biden’s AI chip restrictions

    May 19, 2025

    DOGE software engineer’s computer infected by info-stealing malware

    May 19, 2025

    AI use damages professional reputation, study suggests

    May 19, 2025

    New pope chose his name based on AI’s threats to “human dignity”

    May 18, 2025

    Comments are closed.

    Editors Picks

    1940s railroad car becomes unique tiny house

    May 19, 2025

    Berlin’s Emerge Tech nabs funding to bring AI-powered employer branding to SMEs — no agency needed

    May 19, 2025

    12 Ways to Upgrade Your Wi-Fi and Make Your Internet Faster (2025)

    May 19, 2025

    VMware perpetual license holders receive cease-and-desist letters from Broadcom

    May 19, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Write Down Your Thoughts in a Digital Journal on Your Phone

    January 15, 2025

    How ‘Based’ Is Grok 3? + Robinhood C.E.O. Vlad Tenev on Markets for Everything + Vibecoding 101

    February 21, 2025

    Heart Disease Awareness: When and Why You Should Get Screened Now

    February 5, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.