WordPress Sites Using Everest Forms Need Urgent Updates
A security flaw in a popular WordPress plugin has been used by attackers for two months. If you run a WordPress site with Everest Forms, you need to update now.
Source
SecurityWeek
Original headline: Everest Forms Vulnerability Exploited to Hack WordPress Sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
A serious security problem has been found in Everest Forms, a plugin used by many WordPress websites to create contact forms and surveys. Attackers have been actively exploiting this vulnerability for the past two months. The flaw allows hackers to take control of websites remotely by running their own code on the site. This affects anyone who runs a WordPress website and has installed the Everest Forms plugin. If your site uses this plugin, attackers could potentially access your website's files, steal visitor information, change your content, or use your site to spread malware to visitors.
Even if you only use WordPress for a small family blog or local business site, you are at risk if this plugin is installed. You should take action immediately.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Here is what to do right now:
- Log into your WordPress dashboard and go to the Plugins section.
- Look for Everest Forms in your list of installed plugins.
- If you see it, check if an update is available and install it immediately.
- If you do not use this plugin anymore, delete it completely from your site.
- Check your website for any unusual content or behavior that might indicate it has already been compromised. Going forward, make it a weekly habit to check for WordPress and plugin updates. Enable automatic updates if your hosting provider offers this option. Only install plugins from trusted sources, and remove any plugins you no longer use. Keeping your website software updated is the single most important thing you can do to protect your site and your visitors.
Curated from trusted cybersecurity sources by GetCyberRight
Source: SecurityWeekStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Fake Banking App Updates Are Stealing Money Through Android Phones
Criminals are using fake banking app updates hosted on GitHub to install malware that steals financial data from Android phones.
4 min readFake Banking App Updates Are Installing Malware on Android Phones
A new malware called NFCShare is spreading through fake banking app updates. Here's how to protect your family's financial information.
3 min read
Silent Ransom: Criminals Are Walking Into Offices to Install Malware
A new attack called Silent Ransom combines phone scams with physical office break-ins. Law firms are the first targets, but any small business could be next.
3 min read
Critical Security Flaw in Check Point VPN Under Active Attack
A zero-day vulnerability in Check Point VPN has been exploited since early May, with ransomware groups using it to break into business networks.
3 min read