Hackers Exploit Patched WordPress Bugs, Millions Vulnerable

Gadget Review · top

Millions of WordPress sites remain at risk due to unpatched vulnerabilities. A chainable pair of bugs in the WordPress REST API, known as WP2Shell, allows attackers to achieve full remote takeover without needing login credentials. This exploit targets even fresh, unconfigured WordPress deployments, highlighting a significant security threat to a vast number of websites globally.

हैकर पैच किए गए वर्डप्रेस बग का फायदा उठा रहे, लाखों असुरक्षित

लाखों वर्डप्रेस साइटें अभी भी असुरक्षित हैं क्योंकि उनमें पैच नहीं लगे हैं। वर्डप्रेस REST API में दो बग्स, जिन्हें WP2Shell कहा जाता है, हमलावरों को बिना लॉगिन के पूरी तरह से साइट का कंट्रोल लेने देते हैं। यह खतरा नई और बिना कॉन्फ़िगरेशन वाली वर्डप्रेस साइटों को भी निशाना बना रहा है, जिससे दुनिया भर की कई वेबसाइटों के लिए एक बड़ा सुरक्षा जोखिम पैदा हो गया है।