Blog | G5 Cyber Security

RCE Attempts Against the Latest WordPress REST API Vulnerability

RCE attempts started today after a few days of attackers (mostly defacers) rushing to vandalize as many pages as they could. Attackers in the wild are trying to exploit sites that have plugins that allow for PHP execution from within posts and pages. These plugins, allow users to insert PHP code directly into the posts as a way to make customizations easier. We believe that PHP code should be run within a plugin or theme. It should not be run directly from the posts. We are starting to see them being attempted on a few sites.”]

Source: https://blog.sucuri.net/2017/02/rce-attempts-against-the-latest-wordpress-rest-api-vulnerability.html

Exit mobile version