• Skip to primary navigation
  • Skip to main content
  • Skip to footer
  • Home
  • Advertise With Us
  • Contact
  • Cookie Policy
    • Privacy statement (CA)
    • Cookie policy (CA)
    • Privacy statement (UK)
    • Cookie policy (UK)
    • Privacy statement (US)
    • Cookie Policy (US)
    • Privacy statement (EU)
    • Cookie policy (EU)
    • Disclaimer

TechWalls

Technology News | Gadget Reviews | Tutorials

  • Reviews
  • Tech News
  • Tech Guide
  • Gadget & Apps

WordPress plugins that turn your site into a malware host

Updated on Jul 21, 2014 by Guest Authors

Administrators of WordPress hosted websites and other platforms may not immediately take heed of the updates to their plugins as these are not at all deemed matters of critical need. But if you heard of a recent vulnerability in some WordPress plugins, you might change your attitude towards updating your site to newer versions of WordPress, including its plugins.

Researchers from Sucuri have discovered a significant volume of flaws on such WordPress plugins as WPTouch, Disqus, All In One SEO Pack and MailPoet Newsletters, specifically the older versions of those site components. Which means all you need to do to address the vulnerability is update to the latest versions of those plugins.

The latest versions are as follows: WPTouch version 3.4.3, Disqus v2.77, All In One SEO Pack v2.2.1, MailPoet Newsletters v2.6.9. Check these versions against what you are currently using for your WordPress sites to avoid future compromises.

malware-wordpress

What are the risks?

Once the vulnerability turns to be exploited by attackers, your site could become an anchor of malware, phishing attacks and spammy messages, which hackers could use to infect other websites, all without your knowledge.

As a specific description of the bug, take the mobile plugin WPTouch for example. Attackers could manipulate the flaw in this plugin to infect your site with malicious PHP files or inject backdoor malware into a server easily without having to enter certain administrative rights as a security protocol.

Read also: WordPress accounts vulnerable to hacking due to unencrypted cookies

The security flaw was specifically found on an erroneous WPTouch code, and if attackers have their way earlier than you can respond to the vulnerability, they could take hold of your site and control it for their financial benefit. It also turned out that the chance that an attacker could have unrestricted access to your site is very simple. Either a subscriber or an author can upload the malicious PHP files to the server in order to target your site.

The versions in the series of 3.x are in particular the affected versions of WPtouch, according to researchers. However, those who are using the older versions in the series of 2.x and 1.x are spared from the vulnerability.

Administrators who allow guests to their websites to register or create an account to be able to post comments should be specifically concerned about the flaw as it is targeted against their websites.

The issues affecting the WPtouch plugin are the same concerns that impact the MailPoet plugin as attackers could upload PHP files without having the privilege required to do so. Again, the only solution is update your plugins, better if all of them.

Disclosure: We might earn commission from qualifying purchases. The commission help keep the rest of my content free, so thank you!

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

New iDPRT Printers – SP450, SP420, and Zeva 1966 Photo Printer Reviewed

Munbyn P44S Wireless Thermal Label Printer Review

Master & Dynamic MW75 Wireless Headphones Review – Get Lost in the Music

3DMakerPro Mole 3D Scanner Review – Affordable, Portable, and Easy To Use

Follow TechWalls

YoutubeFacebookTwitterInstagram

Recent Posts

  • New iDPRT Printers – SP450, SP420, and Zeva 1966 Photo Printer Reviewed
  • Munbyn P44S Wireless Thermal Label Printer Review
  • POLYWOOD Classic Folding Adirondack vs Member’s Mark Adirondack Chair – Which Is Better?
  • BLUETTI’s New Expandable Outdoor Solar Generator AC60 & B80

Copyright © 2023 ยท All Rights Reserved

Manage Cookie Consent
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional cookies Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage vendors Read more about these purposes
View preferences
{title} {title} {title}