A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.
The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.
"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."
That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.
The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."
The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.
More articles
- Pentest Tools Framework
- Best Hacking Tools 2019
- Pentest Tools Website Vulnerability
- Hacking Tools Name
- Easy Hack Tools
- Growth Hacker Tools
- Pentest Tools Framework
- Hack Website Online Tool
- Hacker Search Tools
- Hacking Tools
- Pentest Tools Apk
- Pentest Automation Tools
- Game Hacking
- Hacker Security Tools
- Pentest Tools Online
- Hacking Tools Github
- Hacking Tools Download
- Hacker Tools Linux
- Pentest Tools Android
- Pentest Tools
- Game Hacking
- Hacker Tools For Mac
- Hacker Hardware Tools
- New Hack Tools
- Hacking Tools For Kali Linux
- Hacker Tools Windows
- Hack And Tools
- Tools Used For Hacking
- Pentest Tools Nmap
- Hackers Toolbox
- Tools 4 Hack
- What Are Hacking Tools
- Hacker Tools 2020
- Pentest Tools For Ubuntu
- Tools 4 Hack
- Hacking Tools Usb
- Hacking Tools Online
- Hackrf Tools
- Hack Tools
- Hack Tools
- Pentest Tools Free
- Pentest Tools Nmap
- Pentest Tools Review
- Pentest Tools Kali Linux
- Pentest Tools Subdomain
- New Hack Tools
- Hacking Tools For Windows
- Blackhat Hacker Tools
- Install Pentest Tools Ubuntu
- Hacking App
- Top Pentest Tools
- Hacking Tools For Pc
- Hacker Tools Online
- Hacker Hardware Tools
- Pentest Tools Apk
- Hack Tools For Windows
- Pentest Tools Website
- Pentest Tools Port Scanner
- Hacker Hardware Tools
- What Are Hacking Tools
- What Is Hacking Tools
- Hacker Tools Github
- Hack Tools 2019
- Hacking Tools Download
- Hack And Tools
- Hacking Tools For Windows Free Download
- Termux Hacking Tools 2019
- Hacking Tools For Windows 7
- Hacking Tools 2019
- Pentest Tools Nmap
- Hacking Tools 2020
- Hacking Tools For Beginners
- What Are Hacking Tools
- Pentest Tools Nmap
- Hacking Tools 2020
- Hacking Tools For Beginners
- Top Pentest Tools
- Hacker Tools For Ios
- Hack Tool Apk
- Pentest Tools Subdomain
- Hack Tools For Windows
- Hacking Tools Pc
- Tools Used For Hacking
- Hacking Tools For Windows
- Pentest Tools Github
- Hacker Tools For Ios
- Pentest Tools Nmap
- Hacker Tools List
- Hack Tools
- Hacker Tool Kit
- Hacking Tools Free Download
- Hack And Tools
- Pentest Tools Framework
- Hacker Tools
- Hacker Tool Kit
- Hacker Tools For Mac
- Hacker Tools Apk Download
- Top Pentest Tools
- Pentest Tools Bluekeep
- Hacker Tools For Pc
- Pentest Tools List
- Hacking App
- Hacking Tools Online
- Hacking Tools And Software
- Pentest Tools For Android
- Pentest Tools Url Fuzzer
- Hacker Tools Apk
- Nsa Hack Tools
- Hacking Tools 2020
- Hacking App
- Best Hacking Tools 2020
- Pentest Tools Find Subdomains
- Hacking Tools Name
- Hack Tools 2019
- Install Pentest Tools Ubuntu
- Hacking Tools Online
- Pentest Tools Nmap
- Hacking Tools And Software
- Pentest Recon Tools
- Hack Website Online Tool
- Hacker Tools Online
- Top Pentest Tools
- Hacker Hardware Tools
- Hacking Tools Pc
- Hacking Tools Download
- Hack Tools
- Hacking Apps
- How To Install Pentest Tools In Ubuntu
- Hacking Tools And Software
- Hack And Tools
- Hack Tools Github
- Android Hack Tools Github
- Nsa Hack Tools Download
- Best Hacking Tools 2019
- Hacks And Tools
- Hack Tool Apk No Root
- Hacking Tools For Games
- Blackhat Hacker Tools
- Hacker Tools 2020
- Hacking Tools For Windows 7
- Easy Hack Tools
- Hacker Tools 2019
- Pentest Tools Find Subdomains
- Pentest Box Tools Download
- Pentest Tools Url Fuzzer
- Best Hacking Tools 2020
- Hacker Tools Software
- Pentest Tools Website