PT-2023-29423 · WordPress · Wordpress
Published
2023-12-02
·
Updated
2024-02-23
·
CVE-2023-45124
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
WordPress (affected versions not specified)
Description
A phishing campaign is targeting WordPress administrators with fake security advisories regarding a non-existent vulnerability. The emails aim to trick users into installing a malicious plugin, potentially leading to site takeover and remote code execution. The campaign uses a fictitious vulnerability tracked as a non-valid identifier to distribute the backdoor plugin.
Recommendations
As a temporary workaround, consider disabling any recently installed plugins until the issue is resolved.
Restrict access to the WordPress administrator dashboard to minimize the risk of exploitation.
Avoid clicking on links or downloading plugins from unverified sources, especially those claiming to fix non-existent vulnerabilities.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress