Source |
The Hacker News |
Identifiant |
6879725 |
Date de publication |
2022-09-14 07:21:00 (vue: 2022-09-14 04:05:46) |
Titre |
Over 280,000 WordPress Sites Attacked Using WPGateway Plugin Zero-Day Vulnerability |
Texte |
A zero-day flaw in the latest version of a WordPress premium plugin known as WPGateway is being actively exploited in the wild, potentially allowing malicious actors to completely take over affected sites.
Tracked as CVE-2022-3180 (CVSS score: 9.8), the issue is being weaponized to add a malicious administrator user to sites running the WPGateway plugin, WordPress security company Wordfence |
Notes |
|
Envoyé |
Oui |
Condensat |
000 2022 280 3180 actively actors add administrator affected allowing as cve as wpgateway is attacked being company completely cvss day exploited flaw issue known latest malicious over plugin potentially premium running score: security sites take tracked user using version vulnerability weaponized wild wordfence wordpress wpgateway zero |
Tags |
Vulnerability
|
Stories |
|
Move |
|