+91-9560121007

+1-929-243-5550

8 Popular WordPress Plugins Are Currently Being Exploited By Hackers – Search Engine Journal

Flexible Checkout Fields for WooCommerce (20,000 installs)

A zero-day exploit in this plugin allowed attackers to inject XSS payloads, which could then be triggered in the dashboard of a logged-in administrator. Attackers used the XSS payloads to create rogue admin accounts.

Attacks began on February 26. A patch has since been issued.

ThemeREX Addons

A zero-day exploit in this plugin, that comes with all ThemeREX commercial themes, allowed attackers to create rogue admin accounts.

Attacks began on February 18. No patch has been issued for this bug, so site owners are advised to remove the plugin as soon as possible.