Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
What's Hot

SpaceX plans to raise $75B in its IPO by selling 555.6M shares at $135 each, an unusual move since most companies set a price range before the roadshow (Echo Wang/Reuters)

June 3, 2026

Most Companies Are Buying AI Tools Wrong. Here’s How to Fix That.

June 3, 2026

Synopsys (SNPS) Has a Design-Complexity Moat the Chip-Cycle Lens Misses

June 3, 2026
Facebook Twitter Instagram
Wednesday, June 3
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
Subscribe
Business CircleBusiness Circle
Home » Thousands of WordPress sites hit by gift card plugin flaw
Technology

Thousands of WordPress sites hit by gift card plugin flaw

Business Circle TeamBy Business Circle TeamDecember 27, 2022Updated:August 21, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Thousands of WordPress sites hit by gift card plugin flaw
Share
Facebook Twitter LinkedIn Pinterest Email



1000’s of WordPress web sites have been discovered utilizing a vulnerability add-on that permits risk actors to take over the location fully. 

Researchers uncovered a vital flaw in YITH WooCommerce Present Playing cards Premium, an add-on for the web site builder offering an interface to construct present playing cards on WordPress websites, which is reportedly being utilized by greater than 50,000 web sites.

The flaw itself is an unauthenticated arbitrary file add vulnerability, permitting crooks, amongst different issues, to add net shells and achieve full entry to the goal web site.

Stealing crypto account particulars

The vulnerability, tracked as CVE-2022-45359 and given has a severity rating of 9.8 – vital, has since been patched and customers are urged to replace their add-on as quickly as attainable, as there may be proof of the flaw being abused within the wild.

It was first found in late November 2022, when researchers discovered the flaw current in all variations as much as 3.19.0. Therefore, customers are suggested to deliver the add-on to at the least 3.20.0, or 3.21.0 which is now additionally obtainable for obtain. 

The flaw was found by Wordfence, a cybersecurity firm analyzing the WordPress ecosystem, and its researchers declare there are risk actors leveraging the flaw on the market, already. 

Whereas most assaults occurred in November, whereas the flaw was nonetheless thought-about a zero-day, one other peak in utilization was additionally noticed on December 14, 2022. 

Simply two IP addresses (103.138.108.15, and 188.66.0.135) accounted for greater than 20,000 exploitation makes an attempt in opposition to nearly 12,000 web sites. 

Whereas WordPress itself is comparatively steady (round 0.5% of all WordPress-related vulnerabilities fall on the internet internet hosting platform itself), its ecosystem is giant and as such, offers ample alternatives for exploitation. Paid add-ons, comparable to this one, are normally regularly up to date and builders attempt to keep a safe product, whereas free add-ons can usually go for months with out patches and may flip into an actual nightmare for site owners.

By way of: BleepingComputer (opens in new tab)



Source link

card flaw Gift Hit plugin Sites Thousands WordPress
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Business Circle Team
Business Circle Team
  • Website

Related Posts

SpaceX plans to raise $75B in its IPO by selling 555.6M shares at $135 each, an unusual move since most companies set a price range before the roadshow (Echo Wang/Reuters)

June 3, 2026

You hunch over a screen all day. Six small upgrades to relax your tight neck and achy back | Health & wellbeing

June 3, 2026

Amazon has discounted this 75-inch Hisense TV by over $500 – and I highly recommend it

June 2, 2026

elementary OS 8.1 focuses on polish, security, and a smoother Linux desktop

June 2, 2026
LATEST UPDATES

SpaceX plans to raise $75B in its IPO by selling 555.6M shares at $135 each, an unusual move since most companies set a price range before the roadshow (Echo Wang/Reuters)

June 3, 2026

Most Companies Are Buying AI Tools Wrong. Here’s How to Fix That.

June 3, 2026

Synopsys (SNPS) Has a Design-Complexity Moat the Chip-Cycle Lens Misses

June 3, 2026

The AI Perception-Reality Gap

June 3, 2026

Ten US Cities Join Globalist Urban Pact Against Sovereign Nations

June 3, 2026

You hunch over a screen all day. Six small upgrades to relax your tight neck and achy back | Health & wellbeing

June 3, 2026

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Business, Finance and Market Growth News Site

Important Pages
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Recent Posts
  • SpaceX plans to raise $75B in its IPO by selling 555.6M shares at $135 each, an unusual move since most companies set a price range before the roadshow (Echo Wang/Reuters)
  • Most Companies Are Buying AI Tools Wrong. Here’s How to Fix That.
  • Synopsys (SNPS) Has a Design-Complexity Moat the Chip-Cycle Lens Misses
© 2026 BusinessCircle.co
  • Privacy Policy
  • Terms and Conditions
  • Cookie Privacy Policy
  • Disclaimer
  • DMCA

Type above and press Enter to search. Press Esc to cancel.