Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,151,613 members, 7,813,008 topics. Date: Tuesday, 30 April 2024 at 03:38 AM

Combined Attack On Elementor Pro And Ultimate Addons For Elementor - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Combined Attack On Elementor Pro And Ultimate Addons For Elementor (470 Views)

Essential Addons For Elementor Remote Code Execution Vulnerability Discovered / Best Fashion Woocommerce Responsive Wordpress Theme Built On Elementor / Exclusive! Get 70% Off Godaddy Hosting Plans (economy, Deluxe And Ultimate Plans (2) (3) (4)

(1) (Reply)

Combined Attack On Elementor Pro And Ultimate Addons For Elementor by IsuaWP: 5:03am On May 08, 2020
Combined Attack on Elementor Pro and Ultimate Addons for Elementor Puts 1 Million Sites at Risk.

Solution:

If you have pro and site registration enabled, attackers can register and upload malicious files.

If you have site registration disabled, but you have ultimate add ons plugin, they can still register a subscriber through a hole, and upload the files.

If anyone is looking for a free fix, they recommend disabling pro and enabling when an update fix happens. You might lose some pro widgets.

Note, it should also be mentioned that if you have Pro, and you don’t have ultimate add ons, you might be fine by turning off user registration, because a user is required to upload the files.

https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/

(1) (Reply)

I Need Help / Hp Pavilion Or Lenovo Ideapad 110 For web Development? / I NEED A Website But........

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 4
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.