Saturday, May 23, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | News | Critical Plugin Bug Puts Over 2 Lakh Wordpress Websites At Risk Of Hacking

Critical plugin bug puts over 2 lakh WordPress websites at risk of hacking

The bug is present in the Ultimate Member plugin, which is a free user profile WordPress plugin that makes it easy to create powerful online communities and membership sites with WordPress.

By IANS
Updated On - 2 July 2023, 03:47 PM
Critical plugin bug puts over 2 lakh WordPress websites at risk of hacking
Representational Image.
whatsapp facebook twitter telegram

New Delhi: More than 2 lakh WordPress websites are at the hacking risk due to a critical unpatched security vulnerability that was being actively exploited by malicious actors.

According to WordPress security firm WPScan, the bug is present in the Ultimate Member plugin, which is a free user profile WordPress plugin that makes it easy to create powerful online communities and membership sites with WordPress.

Also Read

  • Serious bug in WordPress plugin with over 3 mn installations found
  • 1.2 mn WordPress websites breached, says GoDaddy
  • Trump launches his own social media platform as WordPress blog

“This is a very serious issue as unauthenticated attackers may exploit this vulnerability to create new user accounts with administrative privileges, giving them the power to take complete control of affected sites,” the security firm warned.

There was “no complete fix to this issue” and worryingly, “there were indications that this issue was being actively exploited by malicious actors,” the firm added.

In response to the vulnerability report, the creators of the plugin promptly released a new version, 2.6.4, intending to fix the problem.

“However, upon investigating this update, we found numerous methods to circumvent the proposed patch, implying the issue is still fully exploitable,” the WPScan team noted.

The plugin operates by using a pre-defined list of user metadata keys that users should not manipulate.

It uses this list to check if users are attempting to register these keys when creating an account.

“Unfortunately, differences in how the Ultimate Member’s blocklist logic and how WordPress treats metadata keys made it possible for attackers to trick the plugin into updating some it shouldn’t,” said the team.

The security researchers recommend that the users should disable the Ultimate Member plugin until a patch that completely remediates this security issue is made available.

Sites on WP.cloud hosts, such as WordPress.com and Pressable.com, have received a platform-level patch to help mitigate the vulnerability.

  • Follow Us :
  • Tags
  • hacker
  • Hacking
  • plugin
  • WordPress

Related News

  • Random YouTube livestream mysteriously appears on White House website

    Random YouTube livestream mysteriously appears on White House website

  • Anthropic disrupts AI-driven hacking campaign linked to China

    Anthropic disrupts AI-driven hacking campaign linked to China

  • WhatsApp Scam Alert: How fraudsters hijack accounts and steal money

    WhatsApp Scam Alert: How fraudsters hijack accounts and steal money

  • Beware of formjacking

    Beware of formjacking

Latest News

  • Cyberabad police to enforce traffic diversions at Novopan Junction from May 24

    9 mins ago
  • ‘Drishyam’ actor Ansiba Hassan claims she was called ‘jihadi’, forced to resign

    32 mins ago
  • Gurindervir snatches 100m national record from Animesh Kujur in stunning race

    33 mins ago
  • HCA Unveils 8 franchise owners for inaugural TG20 League

    38 mins ago
  • NEET aspirants to get free Haryana Roadways travel on June 20–21: CM

    40 mins ago
  • Dasoju Sravan opposes centralised grocery procurement for hostels

    48 mins ago
  • Life Sciences Park to be established on lands acquired for Pharma City, says Sridhar Babu

    55 mins ago
  • Narsingi police nab suspect in Alkapur molestation case

    55 mins ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam