• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Daredevil Born Again: S2 spoiler-free review – A brutal triumph

March 25, 2026

Nothing Phone (4a) Pro review: Daringly different

March 19, 2026

9 Hidden iPhone Features You Should Be Using in 2026

March 18, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Tech News»New zero-day vulnerability in BackupBuddy plugin leaves WordPress users at risk
Tech News

New zero-day vulnerability in BackupBuddy plugin leaves WordPress users at risk

September 10, 2022No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
New zero-day vulnerability in BackupBuddy plugin leaves WordPress users at risk
Share
Facebook Twitter LinkedIn Pinterest Email

Why it issues: WordPress plugin developer, iThemes, alerted customers to a vulnerability associated to their BackupBuddy extension earlier this week. The safety gap leaves plugin customers prone to unauthorized entry by malicious actors, offering them with the chance to steal delicate recordsdata and data. The flaw impacts any websites working BackupBuddy 8.5.8.0 by means of 8.7.4.1. Customers ought to replace to model 8.7.5 to patch the opening.

In accordance with iThemes researchers, Hackers are actively exploiting the vulnerability (CVE-2022-31474) throughout impacted techniques utilizing particular variations of the BackupBuddy plugin. The exploit permits attackers to view the contents of any WordPress-accessible file on the affected server. This consists of these with delicate info, together with /and many others/passwd, /wp-config.php, .my.cnf, and .accesshash. These recordsdata can present unauthorized entry to system consumer particulars, WordPress database settings, and even authentication permissions to the affected server as the foundation consumer.

Directors and different customers can take steps to find out if their website was compromised. Licensed customers can overview an impacted server’s logs containing local-destination-id and /and many others/handed or wp-config.php that return an HTTP 2xx response code, indicating a profitable response was acquired.

WordPress safety answer developer Wordfence recognized hundreds of thousands of makes an attempt to use the vulnerability courting again to August twenty sixth. In accordance with Wordfence safety researchers, customers and directors ought to examine server logs for references to the aforementioned local-destination-id folder and the local-download folder. The PSA went on to record the highest IPs related to the tried assaults, which embody:

  • 195.178.120.89 with 1,960,065 assaults blocked
  • 51.142.90.255 with 482,604 assaults blocked
  • 51.142.185.212 with 366,770 assaults blocked
  • 52.229.102.181 with 344,604 assaults blocked
  • 20.10.168.93 with 341,309 assaults blocked
  • 20.91.192.253 with 320,187 assaults blocked
  • 23.100.57.101 with 303,844 assaults blocked
  • 20.38.8.68 with 302,136 assaults blocked
  • 20.229.10.195 with 277,545 assaults blocked
  • 20.108.248.76 with 211,924 assaults blocked
See also  Meta partnership allows Indian WhatsApp users to browse and buy groceries via JioMart – Fintech

Researchers at iTheme present compromised BackupBuddy customers with a number of steps designed to mitigate and stop additional unauthorized entry. These steps embody resetting WordPress database passwords, altering WordPress salts, updating API keys saved within the wp-config.php file, and updating SSH passwords and keys. Clients requiring further assist can submit assist tickets by way of the iThemes Assist Desk.

Picture credit score: Justin Morgan

Source link

BackupBuddy leaves plugin risk Users Vulnerability WordPress ZeroDay
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

9 Common Scams Targeting Mac Users in 2026

February 21, 2026

Oppo A40 review: Absurdly cheap, but for casual users only

August 14, 2025

Stuck in the Past? This Many iPhone Users Haven’t Upgraded to iOS 18

June 7, 2025

Are European iPhone Users About to Start Losing Features?

June 3, 2025
Add A Comment

Comments are closed.

Editors Picks

Starfish Space reveals plan to demonstrate satellite docking in orbit

November 11, 2022

Singapore-based career development platform Glints recruits $50M in new funding – DailyTech

August 30, 2022

Apple Ordered to Pay ‘Cellular Technology Company’ (Patent Troll) Optis $700M+ in UK Patent Ruling

May 2, 2025

Samsung’s Galaxy Watch 5 is on sale for $230 right now

October 24, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Daredevil Born Again: S2 spoiler-free review – A brutal triumph

Nothing Phone (4a) Pro review: Daringly different

9 Hidden iPhone Features You Should Be Using in 2026

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.