{"id":9081,"date":"2020-09-04T02:47:01","date_gmt":"2020-09-04T06:47:01","guid":{"rendered":"http:\/\/local.brightwhiz\/?p=9081"},"modified":"2020-09-04T02:47:01","modified_gmt":"2020-09-04T06:47:01","slug":"file-manager-plugin-vulnerability","status":"publish","type":"post","link":"http:\/\/local.brightwhiz\/file-manager-plugin-vulnerability\/","title":{"rendered":"WordPress Websites Attacked Due to File Manager Plugin Vulnerability"},"content":{"rendered":"\n
Hackers<\/a> have been having a field day exploiting the File Manager Plugin vulnerability in WordPress Websites<\/a> that are outdated. The critical vulnerability is present in versions version 6.8 and older.<\/p>\n\n\n\n WordPress File Manager Plugin is a tool that makes it simple for webmasters to upload, edit, archive, and delete files and folders on their website’s backend.<\/p>\n\n\n\n This plugin is quite popular among WordPress<\/a> developers and has been installed on over 700,000 websites.<\/p>\n\n\n\n Hackers have been exploiting version 6.8<\/a> and below of WordPress File Manager to inject malicious code onto websites without authorization<\/a>. They then create backdoors for future abuse.<\/p>\n\n\n\n One interesting thing about this exploit is that hackers are injecting code and password-protecting compromised sites using the same vulnerability to keep out rival attackers from exploiting the same flaw.<\/p>\n\n\n\n The developers of WordPress File Manager issued an update (version 6.9) on September 1st that resolves the security issue. Users are advised to update their websites<\/a> as soon as possible. Knowing the WordPress community, it could be a while before most if not all of the installations are updated.<\/p>\n\n\n\n For websites that have the File Manager Plugin vulnerability and have already been compromised, it is advisable to reinstall WordPress to clean-up possibly infected core files. One should also change the passwords to databases and all users with administrator privileges. Also, WordPress file system permissions should be reviewed.<\/p>\n","protected":false},"excerpt":{"rendered":" Hackers have been having a field day exploiting the File Manager Plugin vulnerability in WordPress Websites that are outdated. The critical vulnerability is present in versions version 6.8 and older….<\/p>\n","protected":false},"author":1,"featured_media":9082,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,16],"tags":[288,313,320,424,433,452,526,635,636,643,651],"yoast_head":"\n