Blog | G5 Cyber Security

Popular Yuzo WordPress Plugin Exploited to Redirect Users to Scams

A vulnerability in the popular WordPress plugin called Yuzo Related Posts is being targeted by attackers to inject JavaScript into the pages of the site. This JavaScript will cause visitors to be redirected to sites displaying scams, including tech support scams, and sites promoting unwanted software such as browser extensions. On March 30th, 2019, the developer of the plugin removed the plugin from the WordPress plugin directory after a WordPress security company publicly disclosed the vulnerability. This prevented new users from being infected but the 60,000+ existing installs were not notified and thus were vulnerable.

Source: https://www.bleepingcomputer.com/news/security/popular-yuzo-wordpress-plugin-exploited-to-redirect-users-to-scams/

Exit mobile version