Menu
A new WordPress plug-in exploit endangers thousands of websites

A new WordPress plug-in exploit endangers thousands of websites

WP Mobile Detector flaw allowed hackers to install malicious files on servers

Over the past few days, attackers have been exploiting an unpatched vulnerability in WP Mobile Detector, a WordPress plug-in installed on over 10,000 websites.

The plug-in's developer fixed the flaw Tuesday in version 3.6, but in addition to updating immediately, users should also check if their websites haven't already been hacked.

The vulnerability is located in a script called resize.php script and allows remote attackers to upload arbitrary files to the Web server. These files can be backdoor scripts known as Web shells that provide attackers with backdoor access to the server and the ability to inject code into legitimate pages.

The flaw was discovered by WordPress security outfit PluginVulnerabilities.com after it observed requests for the wp-content/plugins/wp-mobile-detector/resize.php even though it didn't exist on its server. This indicated that someone was running an automated scan for that specific file, likely because it had a flaw.

Researchers from Web security firm Sucuri have analyzed the company's firewall logs and discovered exploitation attempts since May 27, four days before the patch was released. It's possible that attackers have known about the exploit even before that date.

WP Mobile Detector, which shouldn't be confused with a different unaffected plug-in called WP Mobile Detect, used to have more than 10,000 active installations at the beginning of May. Now it has around 2,000, but after the exploit was discovered, the plug-in was briefly removed from the WordPress.org plug-ins directory.

According to Plugin Vulnerabilities there is a limiting factor: in order for this flaw to be exploitable, the allow_url_fopen feature needs to be enabled on the server.

Since it's not clear how many websites have been hacked, it's a good idea for WordPress website owners who use this plug-in to check their servers for signs of compromise.

"At this moment the majority of the vulnerable sites are infected with porn spam doorways," Sucuri researcher Douglas Santos said in a blog post. "You can usually find the gopni3g directory in the site root, that contains story.php (doorway generator script), .htaccess and subdirectories with spammy files and templates."

Subscribe here for up-to-date channel news

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards

Revealed at a glitzy bash in Sydney at the Ivy Penthouse, the first StorageCraft Partner Awards locally saw the vendor honour its top-performing partners with ASI Solutions, SMBiT Pro, Webroot, ACA Pacific and Soft Solutions New Zealand taking home the top awards. Photos by Maria Stefina.

StorageCraft celebrates high achievers at its inaugural A/NZ Partner Awards
Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip

​Synnex and Lenovo hosted 18 resellers for an action-packed weekend adventure in RotoVegas, taking in white water rafting on the Kaituna River, as well as quad biking and dinner at Stratosfare​, overlooking Lake Rotorua at the top of Mount Ngongotaha​. Photos by Synnex.

Kiwi resellers make a splash on Synnex and Lenovo RotoVegas road trip
Show Comments