Menu
A new WordPress plug-in exploit endangers thousands of websites

A new WordPress plug-in exploit endangers thousands of websites

WP Mobile Detector flaw allowed hackers to install malicious files on servers

Over the past few days, attackers have been exploiting an unpatched vulnerability in WP Mobile Detector, a WordPress plug-in installed on over 10,000 websites.

The plug-in's developer fixed the flaw Tuesday in version 3.6, but in addition to updating immediately, users should also check if their websites haven't already been hacked.

The vulnerability is located in a script called resize.php script and allows remote attackers to upload arbitrary files to the Web server. These files can be backdoor scripts known as Web shells that provide attackers with backdoor access to the server and the ability to inject code into legitimate pages.

The flaw was discovered by WordPress security outfit PluginVulnerabilities.com after it observed requests for the wp-content/plugins/wp-mobile-detector/resize.php even though it didn't exist on its server. This indicated that someone was running an automated scan for that specific file, likely because it had a flaw.

Researchers from Web security firm Sucuri have analyzed the company's firewall logs and discovered exploitation attempts since May 27, four days before the patch was released. It's possible that attackers have known about the exploit even before that date.

WP Mobile Detector, which shouldn't be confused with a different unaffected plug-in called WP Mobile Detect, used to have more than 10,000 active installations at the beginning of May. Now it has around 2,000, but after the exploit was discovered, the plug-in was briefly removed from the WordPress.org plug-ins directory.

According to Plugin Vulnerabilities there is a limiting factor: in order for this flaw to be exploitable, the allow_url_fopen feature needs to be enabled on the server.

Since it's not clear how many websites have been hacked, it's a good idea for WordPress website owners who use this plug-in to check their servers for signs of compromise.

"At this moment the majority of the vulnerable sites are infected with porn spam doorways," Sucuri researcher Douglas Santos said in a blog post. "You can usually find the gopni3g directory in the site root, that contains story.php (doorway generator script), .htaccess and subdirectories with spammy files and templates."


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

EDGE 2018: Kiwis kick back with Super Rugby before NZ session

EDGE 2018: Kiwis kick back with Super Rugby before NZ session

New Zealanders kick-started EDGE 2018 with a bout of Super Rugby before a dedicated New Zealand session, in front of more than 50 partners, vendors and distributors on Hamilton Island.‚Äč

EDGE 2018: Kiwis kick back with Super Rugby before NZ session
EDGE 2018: Kiwis assess key customer priorities through NZ research

EDGE 2018: Kiwis assess key customer priorities through NZ research

EDGE 2018 kicked off with a dedicated New Zealand track, highlighting the key customer priorities across the local market, in association with Dell EMC. Delivered through EDGE Research - leveraging Kiwi data through Tech Research Asia - more than 50 partners, vendors and distributors combined during an interactive session to assess the changing spending patterns of the end-user and the subsequent impact to the channel.

EDGE 2018: Kiwis assess key customer priorities through NZ research
Show Comments