
WordPress Website Owners: Update Your Forms Plugin Immediately
Hackers are actively breaking into websites using a plugin called Everest Forms Pro. If you run a WordPress site with this plugin, you need to update now.
Source
The Hacker News
Original headline: Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
Hackers are currently attacking websites that use a WordPress plugin called Everest Forms Pro. This plugin helps website owners create contact forms, registration forms, and other types of forms on their sites. A critical security flaw in the plugin allows hackers to take complete control of affected websites. About 4,000 websites currently use this plugin. If you run a WordPress website and use Everest Forms Pro for any of your forms, your entire website could be compromised.
Hackers can use this flaw to execute their own code on your site, which means they can steal customer information, deface your website, install malware, or use your site to attack others. The vulnerability affects all versions of the plugin up to and including version 1.9.
- You need to take action immediately if you use this plugin. First, log into your WordPress dashboard right now. Go to the Plugins section and look for Everest Forms Pro. If you see it listed, check the version number. If it is version 1.9.12 or lower, update it immediately to the latest version. The company has released a patch that fixes this security hole. If you cannot update right away, disable the plugin temporarily until you can install the update. Second, after updating, review your website carefully for any suspicious changes or new administrator accounts you do not recognize. If you find anything unusual, contact a WordPress security professional immediately. For long-term protection, always keep your WordPress plugins updated. Enable automatic updates if possible, or set a weekly reminder to check for updates manually. Only install plugins from reputable developers with good reviews and recent update histories. Remove any plugins you are not actively using, as each plugin represents a potential security risk. Consider using a WordPress security plugin that monitors for vulnerabilities and suspicious activity on your site.
Curated from trusted cybersecurity sources by GetCyberRight
Source: The Hacker NewsStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Fake IT Workers Are Walking Into Offices to Steal Your Data
Ransomware criminals are now sending imposters dressed as tech support directly to businesses. Here's how to protect your workplace from this physical threat.
3 min readFake IT Workers Are Bringing Malware Directly to Your Office
A ransomware group is impersonating tech support staff to physically enter offices and install malware via USB drives. Here's how to protect your workplace.
3 min readWhy Android Auto Is Actually Safer Than Your Car's Built-In System
Contrary to popular belief, using Android Auto or CarPlay makes your family safer on the road. Your phone gets security updates far more often than your car does.
3 min readGas Station Systems Left Wide Open: What It Means for Your Community
Over 900 gas stations have fuel monitoring systems exposed online with no password protection, creating risks that could impact fuel prices and safety in your area.
4 min read