View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

Exploit kits linked to thousands of WordPress sites

Alleged problem with plugin leads to malicious code insertion.

By Jimmy Nicholls

Thousands of WordPress sites are redirecting users to exploit kits because of a plugin that was outed as faulty last December, according to an analyst who works for the security vendor Fox-IT.

Hackers can allegedly use the vulnerability in RevSlider to embed malicious code into websites using iframes, with the bug already reported to be affecting around 3,000 websites.

It follows reports from the security vendor Sucuri that the plugin was at the heart of a malware campaign compromising 100,000 WordPress sites.

Yonathan Klijnsma, a threat intelligence analyst at Fox-IT, wrote on his personal blog: "The payloads that are dropped from the exploit kits are diverse.

"There are reports of [the ransomware] Cryptowall 3.0 being dropped, some banking malware as well as ad fraud; it just depends who rents ‘loads’ on these instances."

The attackers were said to exploit the vulnerability in RevSlider by abusing the plugin to add another admin account, uploading a PHP scripting file, or editing other files on the WordPress installation.

The last of these attacks was even allegedly achieved by changing the file of the plugin SimplePie, highlighting some of the security risks created by using a highly modular system such as WordPress, which can create unexpected coding interactions.

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

Klijnsma said that WordPress admins can mitigate against the attack by updating RevSlider, either through the dashboard or by installing a patching tool if the plugin has been bundled with a theme.

He also noted that website builders should ensure the content management system and plugins are regularly updated, advising that security could also be improved by converting to a static website.

"You could also ask yourself if you really need a dynamic website," he said.

"If you update content constantly you do but if you only update your website every few months consider a static webpage it saves you a lot of trouble."

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU