Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites

A serious security vulnerability in the WordPress plugin WP-Automatic is being actively targeted by threat actors, with the potential to enable site takeovers.

The vulnerability, identified as CVE-2024-27956, has a CVSS score of 9.9 out of 10. It affects all plugin versions older than 3.9.2.0.

According to a WPScan notice this week, this vulnerability, a SQL injection (SQLi) weakness, presents a serious risk because it allows attackers to create admin-level user accounts, upload malicious files, and potentially take complete control of compromised websites.

The problem, according to the firm owned by Automattic, stems from the user authentication method of the plugin, which is easily gotten over to run arbitrary SQL queries against the database using specially constructed requests read more Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *