Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Opinion
    • Opinion Articles
    • Write An Opinion
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
Share
Aa
Tech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
IT Security

Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin

The Elementor Pro WordPress plugin security flaw, described as a case of broken access control, impacting versions 3.11.6 and earlier is open to over 11 million websites globally

Editorial Desk
Last updated: 2023/04/02 at 5:21 PM
Editorial Desk
Share
SHARE

A high-severity vulnerability discovered by NinTechNet researcher Jerome Bruandet on March 18, 2023 in the widely used Elementor Pro WordPress plugin due to a flawed access control in the WooCommerce module utilised by over eleven million websites, is currently being exploited by hackers

Elementor Pro is a WordPress page builder plugin that facilitates the effortless creation of professional-looking websites, even for individuals who lack coding expertise.

The popular website builder plugin includes drag-and-drop functionality, theme building, a collection of templates, custom widget support, and a WooCommerce builder for online shops.

A vulnerability in version 3.11.6 and all preceding versions of the plugin enables authorised users, such as site members or shop customers, to modify site settings and execute a complete takeover of the site.

The researcher stated that the vulnerability is related to a flawed access control on the WooCommerce module (“elementor-pro/modules/woocommerce/module.php”) of the plugin. This flaw allows anyone to alter WordPress options in the database without undergoing proper validation.

The exploit of the vulnerability takes place through an insecure AJAX action called “pro_woocommerce_update_page_option.” This action suffers from inadequate input validation and a deficiency of capability checks.

In a technical writeup about the bug Bruandet says an authenticated attacker can leverage the vulnerability to create an administrator account by enabling registration and setting the default role to “administrator,” change the administrator email address or, redirect all traffic to an external malicious website by changing siteurl among many other possibilities.

It’s crucial to highlight that the exploitation of this specific vulnerability necessitates the installation of the WooCommerce plugin on the site, which triggers the corresponding vulnerable module on Elementor Pro.

PatchStack reports Elementor Plugin bug actively exploited

According to WordPress security firm PatchStack, hackers are currently exploiting the Elementor Pro plugin vulnerability by redirecting site visitors to malicious domains (“away[.]trackersline[.]com”) or uploading backdoors to the breached site.

The backdoors that are uploaded in these attacks have been named wp-resortpark.zip, wp-rate.php, or lll.zip.

This archive contains a PHP script that enables a remote attacker to upload additional files to the compromised server, thus providing them with complete access to the WordPress site. This access can be used to steal data or install further malicious code.

The exploitation of this vulnerability can also have catastrophic consequences for websites that utiliae the plugin, including the redirection of site visitors to malicious domains or the uploading of backdoors to the compromised website.

PatchStack has identified three IP addresses that most of the attacks targeting vulnerable websites originate from. Therefore, it is recommended to add these IP addresses to a blocklist.

  • 193.169.194.63
  • 193.169.195.64
  • 194.135.30.6

If your WordPress website uses Elementor Pro, it is critical to update to version 3.11.7 or newer without delay, as hackers are actively targeting sites that are vulnerable.

In light of these developments, it is imperative that websites using the Elementor Pro WordPress plugin update to version 3.11.7 (the most current version is 3.12.0) as soon as possible. Failure to do so could leave them vulnerable to hackers who are actively targeting sites with this vulnerability.

As the threat of cyberattacks continues to rise, it is crucial for website owners to prioritize cybersecurity and ensure that all plugins and software are up-to-date with the latest security patches. Failure to do so could lead to a devastating data breach or loss of sensitive information.

This is not the first time that WordPress plugins have been targeted by hackers. Last week, WordPress had to perform a forced update of the WooCommerce Payments plugin, which is utilised by online stores

By Editorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article WILL A VPN KEEP YOU SAFE ? Do VPN Connections Really Keep You Safe Online?
Next Article ChatGPT education Critical Thinking tech news ChatGPT May Lead To The Downfall Of Education And Critical Thinking
Hackers exploit bug in Elementor Pro WordPress plugin hack - Tech News

Tech Articles

Impact of the Internet

Impact Of The Internet On Modern Society

The Internet is changing our society. While we once relied…

May 3, 2022
IoT (Internet Of Things) in 2023 - What you need to know

Internet Of Things (IoT) – Everything You Need To Know In 2023

The Internet of Things (IoT) represents a transformative paradigm that…

August 24, 2023
CMS Customer Retention

Why Re-Thinking Your CMS is Crucial for Customer Retention

Re-thinking your CMS can help you streamline your workflow but…

July 30, 2022

Recent News

New research shows that 9 in 10 senior managers believe that phishing attacks are becoming a serious threat to businesses
IT Security

Phishing Attacks Become A Serious Threat To Businesses

8 Min Read
Tech News - IPFS Malware Phishing Attacks
IT Security

IPFS Malware And Phishing Kit Cyberattacks Increase To Epidemic Proportions

13 Min Read
VMware Aria Services IRAP Aust Gov Data protected level - tech news
IT Security

VMware Aria Services IRAP Assessed to Process Australian Government Data at PROTECTED Level

3 Min Read
WordFence 116 Vulnerabilities Disclosed in 88 WordPress Plugins - tech news
IT Security

WordFence Discloses 116 Vulnerabilities Found In 88 WordPress Plugins

3 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

November, 30, 2023

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Tech News – 2023

Welcome Back!

Sign in to your account

Lost your password?