Most of the WordPress sites that have been compromised are the result of attackers exploiting vulnerable versions of the plugins used. A stored cross-site script vulnerability was discovered last week in the popular WordPress Live Chat Support plugin. The vulnerability allows an unauthenticated attacker to update the plugin settings by calling an unprotected “admin_init hook” and injecting malicious JavaScript code everywhere on the site. The patched version for this vulnerability was released on May 16, 2019, and has been fixed for version 8.0.27 and higher.”]

Malicious JavaScript in WordPress Plugins
ByG5 Cyber Security August 1, 2022
Written by
G5 Cyber Security
G5 Cyber Security protects businesses and families from cyber-attacks and breaches. Contact us today for quote.