
Popular WordPress Plugin Has Security Flaw That Lets Hackers Take Over Websites
A widely used contact form plugin for WordPress websites has a critical flaw. Hackers are already exploiting it to take control of sites.
Source
The Hacker News
Original headline: Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
A serious security flaw has been discovered in Everest Forms Pro, a popular plugin used on WordPress websites to create contact forms and surveys. The plugin is installed on approximately 4,000 websites. Hackers have already started exploiting this vulnerability to take complete control of affected websites.
The flaw allows attackers to execute their own code on vulnerable sites remotely. If you run a WordPress website and use Everest Forms Pro for your contact forms or surveys, your site may be at risk. All versions of the plugin up to and including version 1.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
9.12 are vulnerable. Hackers exploiting this flaw can gain complete control of your website, potentially stealing customer information, defacing your site, or using it to attack others. You need to take action immediately if you use this plugin. First, log into your WordPress dashboard right now.
Second, go to your plugins section and check if you have Everest Forms Pro installed. Third, if you do have it, update it immediately to the latest version, which should be newer than 1.9.
- Fourth, if an update is not available yet, consider temporarily deactivating the plugin until a patch is released. Fifth, check your website for any unusual changes or new administrator accounts you did not create. Going forward, make updating your WordPress plugins a regular habit. Set aside time each week to check for updates to your WordPress core software, themes, and all plugins. Consider enabling automatic updates for plugins when possible. Only install plugins from reputable sources with good reviews and regular updates. The longer you wait to update, the more time hackers have to exploit known vulnerabilities.
Curated from trusted cybersecurity sources by GetCyberRight
Source: The Hacker NewsStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Fake IT Workers Are Walking Into Offices to Steal Your Data
Ransomware criminals are now sending imposters dressed as tech support directly to businesses. Here's how to protect your workplace from this physical threat.
3 min readFake IT Workers Are Bringing Malware Directly to Your Office
A ransomware group is impersonating tech support staff to physically enter offices and install malware via USB drives. Here's how to protect your workplace.
3 min readWhy Android Auto Is Actually Safer Than Your Car's Built-In System
Contrary to popular belief, using Android Auto or CarPlay makes your family safer on the road. Your phone gets security updates far more often than your car does.
3 min readGas Station Systems Left Wide Open: What It Means for Your Community
Over 900 gas stations have fuel monitoring systems exposed online with no password protection, creating risks that could impact fuel prices and safety in your area.
4 min read