Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
IT Security

Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin

The Elementor Pro WordPress plugin security flaw, described as a case of broken access control, impacting versions 3.11.6 and earlier is open to over 11 million websites globally

Editorial Desk
Last updated: April 2, 2023 5:21 pm
Editorial Desk
Share
SHARE

A high-severity vulnerability discovered by NinTechNet researcher Jerome Bruandet on March 18, 2023 in the widely used Elementor Pro WordPress plugin due to a flawed access control in the WooCommerce module utilised by over eleven million websites, is currently being exploited by hackers

Elementor Pro is a WordPress page builder plugin that facilitates the effortless creation of professional-looking websites, even for individuals who lack coding expertise.

The popular website builder plugin includes drag-and-drop functionality, theme building, a collection of templates, custom widget support, and a WooCommerce builder for online shops.

A vulnerability in version 3.11.6 and all preceding versions of the plugin enables authorised users, such as site members or shop customers, to modify site settings and execute a complete takeover of the site.

The researcher stated that the vulnerability is related to a flawed access control on the WooCommerce module (“elementor-pro/modules/woocommerce/module.php”) of the plugin. This flaw allows anyone to alter WordPress options in the database without undergoing proper validation.

The exploit of the vulnerability takes place through an insecure AJAX action called “pro_woocommerce_update_page_option.” This action suffers from inadequate input validation and a deficiency of capability checks.

In a technical writeup about the bug Bruandet says an authenticated attacker can leverage the vulnerability to create an administrator account by enabling registration and setting the default role to “administrator,” change the administrator email address or, redirect all traffic to an external malicious website by changing siteurl among many other possibilities.

It’s crucial to highlight that the exploitation of this specific vulnerability necessitates the installation of the WooCommerce plugin on the site, which triggers the corresponding vulnerable module on Elementor Pro.

PatchStack reports Elementor Plugin bug actively exploited

According to WordPress security firm PatchStack, hackers are currently exploiting the Elementor Pro plugin vulnerability by redirecting site visitors to malicious domains (“away[.]trackersline[.]com”) or uploading backdoors to the breached site.

The backdoors that are uploaded in these attacks have been named wp-resortpark.zip, wp-rate.php, or lll.zip.

This archive contains a PHP script that enables a remote attacker to upload additional files to the compromised server, thus providing them with complete access to the WordPress site. This access can be used to steal data or install further malicious code.

The exploitation of this vulnerability can also have catastrophic consequences for websites that utiliae the plugin, including the redirection of site visitors to malicious domains or the uploading of backdoors to the compromised website.

PatchStack has identified three IP addresses that most of the attacks targeting vulnerable websites originate from. Therefore, it is recommended to add these IP addresses to a blocklist.

  • 193.169.194.63
  • 193.169.195.64
  • 194.135.30.6

If your WordPress website uses Elementor Pro, it is critical to update to version 3.11.7 or newer without delay, as hackers are actively targeting sites that are vulnerable.

In light of these developments, it is imperative that websites using the Elementor Pro WordPress plugin update to version 3.11.7 (the most current version is 3.12.0) as soon as possible. Failure to do so could leave them vulnerable to hackers who are actively targeting sites with this vulnerability.

As the threat of cyberattacks continues to rise, it is crucial for website owners to prioritize cybersecurity and ensure that all plugins and software are up-to-date with the latest security patches. Failure to do so could lead to a devastating data breach or loss of sensitive information.

This is not the first time that WordPress plugins have been targeted by hackers. Last week, WordPress had to perform a forced update of the WooCommerce Payments plugin, which is utilised by online stores

By Editorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article WILL A VPN KEEP YOU SAFE ? Do VPN Connections Really Keep You Safe Online?
Next Article ChatGPT education Critical Thinking tech news ChatGPT May Lead To The Downfall Of Education And Critical Thinking
Hackers exploit bug in Elementor Pro WordPress plugin hack - Tech News

Tech Articles

Starting a small business venture in Australia

Starting A Small Business Venture In Tough Economic Times

When starting a small business venture in Australia it's worth…

December 8, 2024
Remote Work Trust & Rapport Team Members

How To Build Trust & Rapport With Remote Team Members

Building trust with a remote team members can feel like…

November 23, 2024
Healthcare AI

AI Is Transforming Healthcare By Improving Workflows And Resource Management

Artificial Intelligence (AI) is transforming every industry. In healthcare, there…

October 12, 2024

Recent News

ConnectID for Aussie Digital Identity
IT Security

ConnectID Continues to Tick all the Right Boxes For Data Security

5 Min Read
Radware launches new cloud security centres
IT Security

Radware Launches New Cloud Security Centres in Australia New Zealand and Toronto

3 Min Read
Zero Trust Study
IT Security

Zero Trust Security Study Underscores The Urgency To Implemen Robust Cyber Measures

4 Min Read
New research shows that 9 in 10 senior managers believe that phishing attacks are becoming a serious threat to businesses
IT Security

Phishing Attacks Become A Serious Threat To Businesses

8 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

December, 10, 2024

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2024

Welcome Back!

Sign in to your account