WordPress Security on Stake


(Ananova News) January 04, 2023.

WordPress plugin flaws leveraged by novel Linux malware

Recently, a security alert revealed that WordPress websites on Linux were targeted by a previously unknown strain of Linux malware that exploits flaws in over two dozen plugins and themes to compromise vulnerable systems. The targeted websites were injected with malicious JavaScript retrieved from a remote server. As a result, when visitors click on any area of an infected page, they are redirected to another arbitrary website of the attacker’s choice.

The disclosure comes weeks after Fortinet FortiGuard Labs detailed another botnet called GoTrim that’s designed to brute-force self-hosted websites using the WordPress content management system (CMS) to seize control of targeted systems. In June 2022, the GoDaddy-owned website security company shared information about a traffic direction system (TDS) known as Parrot that has been observed targeting WordPress sites with rogue JavaScript that drops additional malware onto hacked systems. Last month, Sucuri noted that more than 15,000 WordPress sites had been breached as part of a malicious campaign to redirect visitors to bogus Q&A portals. The number of active infections currently stands at 9,314. January 03, 2023, Bleeping Computer reports thirty security vulnerabilities in numerous outdated WordPress plugins and themes are being leveraged by a novel Linux malware to facilitate malicious JavaScript injections. Dr. Web reported that malware compromised both 32- and 64-bit Linux systems, and uses a set of successively running hardcoded exploits to compromise WordPress sites.

Outdated and vulnerable plugins and themes

It involves weaponizing a list of known security vulnerabilities in 19 different plugins and themes that are likely installed on a WordPress site. These infected themes or plugins prompt the malware to retrieve malicious JavaScript from its command-and-control server prior to script injection. The hacker can deploy an implant to target specific websites to expand the network for phishing and malvertising campaigns, as well as malware distribution initiatives.

Doctor Web revealed the targeted plugins and themes –

  • WP Live Chat Support
  • Yuzo Related Posts
  • Yellow Pencil Visual CSS Style Editor
  • Easy WP SMTP
  • WP GDPR Compliance
  • Newspaper (CVE-2016-10972)
  • Thim Core
  • Smart Google Code Inserter (discontinued as of January 28, 2022)
  • Total Donations
  • Post Custom Templates Lite
  • WP Quick Booking Manager
  • Live Chat with Messenger Customer Chat by Zotabox
  • Blog Designer
  • WordPress Ultimate FAQ (CVE-2019-17232 and CVE-2019-17233)
  • WP-Matomo Integration (WP-Piwik)
  • ND Shortcodes
  • WP Live Chat
  • Coming Soon Page and Maintenance Mode
  • Hybrid
  • Brizy
  • FV Flowplayer Video Player
  • WooCommerce
  • Coming Soon Page & Maintenance Mode
  • Onetone
  • Simple Fields
  • Delucks SEO
  • Poll, Survey, Form & Quiz Maker by OpinionStage
  • Social Metrics Tracker
  • WPeMatico RSS Feed Fetcher, and
  • Rich Reviews

Technical experts always suggest keeping software (theme, plugins, third-party add-ons & WordPress Core) updated and up-to-date with the latest fixes. Always use strong and unique logins and passwords to secure accounts. Hence, it is always suggested to have managed WordPress Hosting, as the provider monitors website security, takes regular backup, and always keep them up.

The companies like WordPress.com have got the expertise to protect hosted websites from cyber attacks, breaches, hacking, Identity and access management (IAM), Malware and Vulnerabilities, and Phishing. They take care of updating WordPress core, themes, plugins, and PHP, disabling external URL requests, and implementing SSL. They keep regular backups which ensure business continuity. A secured website has a good online reputation, thus businesses prioritise security. Every eCommerce store and business website needs protection against cyberattacks, malware, & viruses. Businesses want to protect data as well as sensitive information and thus want to ensure website functionality and online reputation. Hence, asks for crucial security measures. Google penalises or blacklists malwarised or phishing websites.

WordPress Plugin for Events


Why use WordPress Plugin for Events Management

WordPress Plugin for Events management is widely used now-a-days. It was used primarily for blogging, but these days they are mainly used for event driven website making. It is PHP based framework software that uses MySQL as data base. WordPress Plugin enriches content management system. It helps to manage contents perfectly. It makes website developing easy and devoid of any hassles.

Now you must understand what a plugin is. A plugin is a basic software developing tool that does not have an independent existence like other software. It works when it is attached to another web development kit or content management system like WordPress. Suppose you are trying to develop a website, a plugin like Event Calender will be very useful.

Event managers use event organizers to mange event in a WordPress website. Some built in plugins like “Customesmpost type” to manufacture events that have same functionality like posting a date with year in a website. The other event organizers use WordPress plugins for the ease with which it can be installed and customized. Again the plugins are very developed. Event organizers use mainly these WordPress Plugin for Events:

  1. Event scheduler/calendar : This is an Ajax oriented searching output screen like Google or yahoo calendar. This event manager gives you the facilities like managing appointments, schedules and upcoming schedules on task bar.By clicking the task bar a user can manage or customize the events with calendar date.
  2. Amr-ical events list : Any user can use this WordPress plugin for Events to manipulate the calendar widgets.
  3. MEM or Minimalistic Event Manager : It is used by the developer to develop flexible event dates. Event dates can be added to a post sent by any user.
  4. Eventify : This is also a popular plugin which will let you edit pop ups and widgets.
  5. Event Brite : This plugin helps you to manage registrations and ticket sales.

Many other tools are available to manipulate events .some of them are free of cost and some of them are paid, but the main thing WordPress plugin for Events provides is easy optimization of user interfacing events.

There are many events made by the programmers to achieve their target for event management. Those WordPress plugin for Events are used in online newspapers to make it user-friendly. A user can search the news by clicking the calendar event for a particular day .Bloggers are also facilitated by those events, as they post their blog in time frame basis. WordPress plugin for Events manager manages those posts timely.

Word press plugin for Events are made by the programmers in daily basis to enrich the event management system. Most of them are free and you can search your needed manager to accomplish your task. As it is a technical issue of installing and using them perfectly, only a good web developer can add them to your website that will make it run properly. So you have to know what you need and then ask your web developer for an appropriate Word press plugin for Events.

JW Player Plugin for WordPress

JW Player plugin for WordPress.com VIP provides publishers to stream, publish, and monitor video with the JW Player, directly within the WordPress. Video uploads and embeds can be performed directly within the WordPress post or page editor. Now WordPress VIP customers can get full access of the JW Player and JW Platform. The player aim is to make it simple for publishers to deliver broadcast quality videos to their audience. JW Player plugin have some key features::

  • Fast video streaming playback across browsers, in both HTML5 and Flash modes.
  • Inline Library Search, Upload, Click-to-Publish.
  • Instant click-to-publish for a specific video you want to embed from your JW platform library using the inline search.
  • Keep the video playing back in your WordPress VIP site secure by using videos URL signing abilities to protect embedded video.
  • Seamless integration & full support for the JW Player.
  • Quick tags to locate custom players.
  • Support for uploading videos using our custom widget.

WordPress For Your Online Training Site


WordPress For Your Online Training Site

You are building an online training site for your employees on new software they’ll have to work with. Where do you begin, and how do you do it easily? Rely on WordPress and a plugin called WP Courseware!

wordpress