This WordPress plugin for Elementor leaves websites vulnerable to hackers


If your website is powered by the WordPress page-builder Elementor, double-check if you’re using this popular plugin. Because, if you are, hackers can easily stage a complete takeover of your website thanks to a newly discovered security flaw.

Security researchers at Patchstack have released a new report(opens in a new tab) about a concerning cybersecurity issue related to the WordPress plugin Essential Addons for Elementor. The plugin provides users with an assortment of pre-built WordPress blocks and templates for use when creating or updating their website.

“This plugin suffers from an unauthenticated privilege escalation vulnerability and allows any unauthenticated user to escalate their privilege to that of any user on the WordPress site,” writes Patchstack in its report.

Basically, malicious actors can take advantage of this to reset the password of any user, including the administrator’s account. If that latter account’s password is reset, a hacker could basically have access to the entire website – backend and all – and take control of the site from its rightful owner. If a targeted website stores user information, this bad actor would have access to and control of that as well.

“This vulnerability occurs because this password reset function does not validate a password reset key and instead directly changes the password of the given user,” explains Patchstack.

Update the plugin as soon as possible

The plugin vulnerability has since been patched and Essential Addons for Elementor users are being urged to update to version 5.7.2. All versions of the plugin prior, going back to version 5.4.0, are affected by the vulnerability. So, be sure to update the plugin!

More than 43 percent(opens in a new tab) of all of the websites on the internet use WordPress. Elementor is a popular website builder for WordPress-powered sites. More than 12 million(opens in a new tab) WordPress-sites utilize Elementor. According to the WordPress Plugin Directory, more than 1 million(opens in a new tab) active websites have the Essential Addons for Elementor installed.





Source link: https://mashable.com/article/wordpress-essential-addons-for-elementor-plugin-security-flaw

Sponsors

spot_img

Latest

Billy Donovan reacts to ex-Florida star Al Horford sinking Bulls with 3-pointer

Al Horford's dagger 3-pointer came at expense of his college coach originally appeared on NBC Sports BostonAl Horford attempted just four 3-pointers over...

Understanding the risks of generative AI for better business outcomes

Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More Any...

Nike’s .SWOOSH is Bringing Polygon NFTs to EA Sports

Nike is expanding its Web3 strategy.  The global sports footwear company is now partnering with EA...

The 5 most interesting things about the NBA’s worst teams

With less than a month left in the 2023-24 NBA regular season, most of us have trained our attention toward the top of...