WordPress Site Owners: Update Everest Forms Plugin Immediately to Prevent Hacking
A security flaw in a popular WordPress form plugin has been exploited by attackers for two months. Site owners need to update now.
Source
SecurityWeek
Original headline: Everest Forms Vulnerability Exploited to Hack WordPress Sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
A serious security vulnerability in Everest Forms, a plugin used by WordPress websites to create contact forms and surveys, has been actively exploited by hackers. The flaw allows attackers to remotely take control of websites without needing any login credentials. This exploitation has been happening in the wild for two months. If you run a WordPress website and use the Everest Forms plugin, your site could be vulnerable or may have already been compromised. Attackers can use this flaw to inject malicious code, steal visitor information, redirect users to harmful websites, or completely take over your site.
Even if you only use your site for a small business, family blog, or community organization, it can be targeted.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Here is what you need to do right now:
- Log into your WordPress dashboard immediately.
- Go to Plugins and look for Everest Forms.
- Update the plugin to the latest version. If an update is available, install it immediately.
- If you cannot update right away, deactivate and delete the Everest Forms plugin until you can safely update it.
- Check your website for any unusual pages, posts, or user accounts you did not create.
- Consider having a web professional review your site if you are unsure whether it was compromised. Going forward, make updating your WordPress plugins a regular habit. Set a monthly reminder to check for updates, or enable automatic updates for plugins when possible. Most WordPress hacks happen because of outdated plugins, not because of sophisticated attacks. Keeping everything current is your best defense against these types of threats.
Curated from trusted cybersecurity sources by GetCyberRight
Source: SecurityWeekStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Fake Banking App Updates Are Stealing Money Through Android Phones
Criminals are using fake banking app updates hosted on GitHub to install malware that steals financial data from Android phones.
4 min readFake Banking App Updates Are Installing Malware on Android Phones
A new malware called NFCShare is spreading through fake banking app updates. Here's how to protect your family's financial information.
3 min read
Silent Ransom: Criminals Are Walking Into Offices to Install Malware
A new attack called Silent Ransom combines phone scams with physical office break-ins. Law firms are the first targets, but any small business could be next.
3 min read
Critical Security Flaw in Check Point VPN Under Active Attack
A zero-day vulnerability in Check Point VPN has been exploited since early May, with ransomware groups using it to break into business networks.
3 min read