Researchers uncovered a new site take over the campaign that targeting WordPress websites by exploiting the multiple WordPress Plugin Zeroday vulnerabilities.
3 popular WordPress plug-ins are exploited as a part of this ongoing site take over attack campaign.
In results, Attackers create a rogue administrator account to infect with a site with the backdoor for future attacks.
Plugin Zeroday Vulnerabilities
The same type of Unauthenticated Stored XSS Zero vulnerability recently patched in the Flexible Checkout Fields for WooCommerce plugin which allowed attackers to modify the plugin’s settings.
Wordfence researchers reported 3rd unauthenticated Stored XSS in 10Web Map Builder for Google Maps, which has installed in 20,000 WordPress websites.
According to Wordfence report ” The vulnerability in 10Web Map Builder exists in the plugin’s setup process. The plugin’s setup functions are called during
10Web Map Builder for Google Maps urges users to update to version 1.0.64 as soon as possible.
Lastly, Multiple Subscriber+ Stored XSS vulnerabilities reported in Modern Events Calendar Lite which installed in 40, 000 websites.
Researchers observed that Modern Events Calendar Lite registers several AJAX actions for login in users that allowed low privileged users such as a subscriber to manipulate the data and they can be injected with various XSS payloads.
It depends on where the attacker injecting the code and this campaign currently targeting administrators to create rogue accounts for the attackers.
This vulnerability has been fixed now. Update to version 5.1.7 as soon as possible.