HT TECH wants to start sending you push notifications. Click allow to subscribe

Shocking cyberattack! 280000 WordPress sites attacked by hackers

WordPress sites have been attacked by Zero-day vulnerability CVE-2022-3180. More than 280000 are exploited.

By: HT TECH
Updated on: Sep 15 2022, 15:58 IST
WordPress sites have been attacked by Zero-day vulnerability CVE-2022-3180! (Stephen Phillips/Hostreviews)

WordPress premium plugin WPGateway has reported a zero-day flaw being actively exploited in the wild. Dubbed as CVE-2022-3180 (CVSS score: 9.8), it is allowing malicious actors to completely take over victim’s sites.The bug is being used to add a malicious administrator user to the sites running the WPGateway plugin, said Wordfence. "Part of the plugin functionality exposes a vulnerability that allows unauthenticated attackers to insert a malicious administrator," noted Wordfence researcher Ram Gall. Shockingly, as many as 280000 such sites have been attacked.

WPGateway login compromised? Here is how to find out

WPGateway is used to install, backup, and clone WordPress plugins and themes from a unified dashboard. The administrator that is running the compromised plugin comes with the username "rangex." Additionally, the appearance of requests to "//wp-content/plugins/wpgateway/wpgateway-webservice-new.php?wp_new_credentials=1" is also a sign that the WordPress site has been compromised using the flaw.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

According to Wordfence, the bug has been used to conduct over 4.6 million attacks attempting to take advantage of the vulnerability against more than 280000 sites in the past 30 days.The operators of WPGateway got to know about the vulnerability on September 8, but it is still an active threat in the wild.

Also read: Looking for a smartphone? To check mobile finder click here.

Administrators of WordPress websites utilising WPGateway are advised to search for the addition of an administrator titled ‘rangex.’ Since the vulnerability is yet to be patched, users are recommended to remove the plugin from their WordPress installations until a fix is rolled out. “If you have the WPGateway plugin installed, we urge you to remove it immediately until a patch is made available and to check for malicious administrator users in your WordPress dashboard,” shared Wordfence in a blog post.

This is not the first time that WordPress sites have been exposed to vulnerabilities. Last year, over 90,000 websites were reported to be taken over because of a flaw in Brizy Page Builder that provides users with a ‘no-code’ website building experience.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 15 Sep, 15:58 IST
Tags:

Sale

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Strix G17 G712LU EV078T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹81,990₹113,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS