Close Menu
  • Home
  • SEO
  • Digital Marketing
  • SEM
  • Marketing Trends
  • Email Marketing

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

test page

25 August 2025

SEO Content Has a Packaging Problem — Whiteboard Friday

12 October 2024

Google Shows 3 Ways To Boost Digital Marketing With Google Trends

12 October 2024
Facebook X (Twitter) Instagram Threads
Avenue AdsAvenue Ads
  • Home
  • SEO
  • Digital Marketing
  • SEM
  • Marketing Trends
  • Email Marketing
Facebook X (Twitter) Instagram
Avenue AdsAvenue Ads
SEO

WordPress Website Builder Vulnerability Affects Nearly 1 Million Websites

avenueadsBy avenueads1 February 2024No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
WordPress Website Builder Vulnerability Affects Nearly 1 Million Websites
Share
Facebook Twitter LinkedIn Pinterest Email

[ad_1]

A big vulnerability has been patched within the Web site Builder by SeedProd that has over 900,000 installations. This vulnerability, current in variations as much as and together with 6.15.21, poses a danger for unauthorized information modification on WordPress websites.

Vulnerability Particulars: Lacking Functionality Test

The vulnerability that was found is named a lacking functionality verify throughout the ‘seedprod_lite_new_lpage’ perform.

Capabilities are particular actions that customers or roles are allowed to carry out. A functionality verify is a crucial safety characteristic in WordPress for managing permissions and entry controls. They decide if a consumer has the authority to carry out particular motion.

It’s much like a task verify in {that a} position verify verifies the consumer’s position (like administrator, editor, and so on.), whereas a functionality verify verifies whether or not the consumer has particular permissions. A functionality verify gives a extra granular management over permissions in comparison with a task verify.

The lacking functionality verify permits unauthenticated attackers to doubtlessly modify the content material of assorted pages created utilizing the plugin, similar to coming-soon or upkeep pages. The absence of this safety characteristic exposes web sites to dangers of information tampering.

Unauthorized Knowledge Modification

Unauthorized modification of information is a critical safety concern. It arises from a flaw the place unauthorized people can alter information, resulting in potential exploits. Addressing this sort of vulnerability within the Web site Builder plugin is extremely advisable.

Severity and Affect: Excessive-Threat Publicity

The vulnerability is rated 8.2 out of a scale of 1- 10, with a severity ranking labeled as ‘Excessive’ in accordance with the Widespread Vulnerability Scoring System (CVSS). The excessive ranking signifies how critical the potential influence is.

This vulnerability is so new that there’s at the moment no entry within the Nationwide Vulnerability Database for the assigned CVE quantity CVE-2024-1072.

Nevertheless, Wordfence WordPress safety researchers emphasised the seriousness of the Website Builder by SeedProd vulnerability:

“This makes it doable for unauthenticated attackers to vary the contents of coming-soon, upkeep pages, login and 404 pages arrange with the plugin.”

Advice For Web site Builder Plugin Customers

The writer of the Web site Builder by SeedProd has responded by releasing an up to date model, 6.15.22, which addresses this vulnerability. The replace features a safety nonce to mitigate the danger, and customers of the plugin are strongly suggested to replace instantly to safe their web site in opposition to assaults.

Relating to the nonce, WordPress explains what it’s:

A nonce is a “quantity used as soon as” to assist defend URLs and kinds from sure kinds of misuse, malicious or in any other case.

…They assist defend in opposition to a number of kinds of assaults…”

Learn the announcement by Wordfence:

Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 – Missing Authorization via seedprod_lite_new_lpag

Read the official SeedProd Changelog

Featured Picture by Shutterstock/Nikulina Tatiana

[ad_2]

Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
avenueads
  • Website

Related Posts

SEO Content Has a Packaging Problem — Whiteboard Friday

12 October 2024

Google Shows 3 Ways To Boost Digital Marketing With Google Trends

12 October 2024

Google Ads announces 11-year data retention policy

12 October 2024

Reddit Makes Game-Changing Updates to Keyword Targeting

11 October 2024
Add A Comment
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Advertisement
Editors Picks

10+ Super SMART Goal Examples (& A Handy Template)

22 August 2024
8.5

Apple Planning Big Mac Redesign and Half-Sized Old Mac

5 January 2021

Autonomous Driving Startup Attracts Chinese Investor

5 January 2021

Onboard Cameras Allow Disabled Quadcopters to Fly

5 January 2021
Top Reviews
9.1

Review: T-Mobile Winning 5G Race Around the World

By avenueads
8.9

Samsung Galaxy S21 Ultra Review: the New King of Android Phones

By avenueads
8.9

Xiaomi Mi 10: New Variant with Snapdragon 870 Review

By avenueads
Advertisement

Type above and press Enter to search. Press Esc to cancel.