More than 50,000 websites use, WordPress plug-in YITH WooCommerce gift card is exposed "key" loophole
CTOnews.com, December 24 (Xinhua)-- hackers are actively exploiting a "critical" vulnerability in the WordPress plugin YITH WooCommerce Gift Cards Premium to extract site permissions and upload malware.
CTOnews.com learned that YITH WooCommerce Gift Cards Premium is a very popular WordPress plug-in, currently used by more than 50, 000 websites around the world. This vulnerability tracking number is CVE-2022-45359 (CVSS v3 9.8), which allows unauthenticated attackers to gain all privileges on the site and upload malicious files to the site.
The CVE-2022-45359 vulnerability was disclosed to the public on November 22, 2022, affecting all plug-in versions prior to 3.19.0. In order to solve this problem, WordPress users need to upgrade to the new version 3.20.0 or above as soon as possible, and the supplier has released 3.21.0, so it is recommended that users upgrade as soon as possible.
Unfortunately, many websites are still using old, vulnerable versions, and hackers have designed effective vulnerabilities to exploit them. According to Wordfence's WordPress security experts, the exploit is well under way, and hackers use the vulnerability to upload backdoors on the website, obtain remote code execution, and carry out takeover attacks.