50,000 Websites Hacked Through MailPoet WordPress Plugin Vulnerability

The users of WordPress, a free and open source blogging tool as well as content management system (CMS), that have a popular unpatched wordPress plugin installed are being cautioned to upgrade their sites immediately.
A serious vulnerability in the WordPress plugin, MailPoet, could essentially allows an attacker to inject any file including malware, defacements and spam, whatever they wanted on the server and that too without any authentication.
MailPoet, formerly known as Wysija Newsletter, is a WordPress plugin with more than 1.7 million downloads that allows developers running WordPress to send newsletters and manage subscribers within the content management system.
In a blog post, the security researcher and CEO of the security firm Sucuri, Daniel Cid, pointed out the vulnerability to be serious and said that within three weeks since the vulnerability unveiled, over 50,000 websites have been remotely exploited by the cybercriminals to install backdoors targeting the vulnerable MailPoet plugin. Read more

Bohn Inc

Share
Published by
Bohn Inc

Recent Posts

Media hackers behind E-toll billing problems: Minister

Minister of Transport Dipuo Peters has said that “some media houses” were responsible for “cyber…

12 years ago

After Takedown, GameOver Zeus Banking Trojan Returns Again

A month after the FBI and Europol took down the GameOver Zeus botnet by seizing…

12 years ago

Smart LED Lightbulbs Can be Hacked too; Vulnerability exposes Wi-Fi Passwords

Until now, we have seen how different smart home appliances such as refrigerators, TVs and…

12 years ago

How To Jailbreak iOS 7.1 And 7.1.1 Untethered Using ‘Pangu’ Jailbreak Tool

Quite Surprisingly, a team of Chinese hackers, Pangu have released an untethered jailbreak for iOS…

12 years ago

New Banking Malware with Network Sniffer Spreading Rapidly Worldwide

With online banking becoming routine for most users, it comes as no surprise that we…

12 years ago

Microsoft Seized No-IP Domains

In an effort to crackdown on cyber crimes, Microsoft has taken a legal action against…

12 years ago