Millions of WordPress Sites at Risk as Hackers Exploit Plugin Vulnerabilities

TL;DR Summary
Hackers are exploiting a critical vulnerability in the Elementor Pro WordPress plugin, which is running on over 12 million sites, to take complete control of websites. The vulnerability allows anyone with an account on the site to create new accounts with full administrator privileges. The flaw was discovered by a security researcher and patched by Elementor last week, but researchers at PatchStack report that the vulnerability is under active exploitation. Users of Elementor Pro should ensure they are running version 3.11.7 or later and check their sites for signs of infection.
- Hackers exploit WordPress plugin flaw that gives full control of millions of sites Ars Technica
- Hackers Exploiting WordPress Elementor Pro Vulnerability: Millions of Sites at Risk! The Hacker News
- Hackers exploit bug in Elementor Pro WordPress plugin with 11M installs BleepingComputer
- View Full Coverage on Google News
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
3 min
vs 3 min read
Condensed
85%
600 → 91 words
Want the full story? Read the original article
Read on Ars Technica