• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Plugins/About 1 million Wordpress pages are vulnerable to a bug that is very easy to exploit, but there is a solution

About 1 million WordPress pages are vulnerable to a bug that is very easy to exploit, but there is a solution

800,000 WordPress pages are still vulnerable to attack because users are forgetting to patch their WordPress sites.

Remember that weeks ago two critical bugs were found in a popular WordPress plugin and although they were patched weeks ago, Hundreds of thousands of users have yet to deploy the update, which puts your sites at risk.

El plugin “All in One” SEO WordPress era vulnerable a dos fallos: CVE-2021-25036, which is a critical authenticated privilege escalation flaw, and CVE-2021-25037, an authenticated SQL injection high severity bug.

Wix’s controversial campaign against WordPress

Missing people to update the patch

In total, it was estimated that three million sites were vulnerable to error. In the last two weeks, since the plugin developers released the patch, more than two million plugins have been updated, resulting in some 820,000 remain vulnerable.

A security breach steals the data of 1.2 million WordPress users: this was the attack that could lead to phishing

Although the flaws require the attacker to authenticate with WordPress, they only need low-level permissions, such as Subscriber, to function. Typically a subscriber can only post comments and edit their own profile, but with CVE-2021-25036, they can elevate their privileges and remotely execute code on vulnerable websites.

Automattic security researcher Marc Montpas, who was the first to spot the flaws, says it’s easy to take advantage of these bugs, as all the attacker has to do is change “a single character to uppercase” to bypass all of them. privilege checks.

The website administrators who use the All in One SEO WordPress plugin should be updated to version 4.1.5.3, of December 14, 2021, to avoid being vulnerable to attacks.

Source link

Written by:
Abdul Wahid
Published on:
December 25, 2021

Categories: Plugins

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter