By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit Patched WordPress Bugs, Threatening Millions of Sites
Hackers are actively exploiting two critical security vulnerabilities in WordPress, a content management system used by an estimated 43% of all websites on the internet. These flaws, which were recently patched by the WordPress security team, allow attackers to gain remote control over affected sites. Cybersecurity researcher Jerod Estes of Wordfence highlighted the severity of the situation, estimating that tens of millions of websites could be at risk if they have not yet updated their WordPress installations. The vulnerabilities, identified as CVE-2024-25998 and CVE-2024-25999, were patched in WordPress version 6.4.3, released on February 6, 2024. The first vulnerability, CVE-2024-25998, is a critical SQL injection flaw within the `wp_parse_request` function, allowing unauthenticated attackers to execute arbitrary SQL commands. The second, CVE-2024-25999, is a critical authentication bypass vulnerability in the REST API, enabling unauthenticated attackers to gain administrative privileges. Wordfence reported that they observed exploitation attempts for both vulnerabilities starting on February 8, 2024, just two days after the patch was released. This rapid exploitation underscores the urgency for website administrators to apply the latest security updates. Failure to do so leaves websites vulnerable to data breaches, defacement, and the deployment of malicious software. The WordPress security team and researchers like Estes are urging all users to update their core WordPress software, as well as their themes and plugins, to the latest versions to mitigate these threats. The widespread adoption of WordPress means that even a small percentage of unpatched sites represents a significant number of potential targets for malicious actors.
Original source — read the full reporting at the publisher:
Read on TechCrunchGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.