Menu Close

Huge WordPress hack wreaking havoc online, 2 million websites defaced

Update your WordPress website to version 4.7.2 if you haven’t do so already

If you haven’t upgraded your WordPress website to the latest version of WordPress 4.7.2, I strongly recommend that you do so as soon as possible. A critical vulnerability was recently discovered and fixed that leaves WordPress websites vulnerable to defacement, or worse.

If left unpatched, the vulnerability allows a hacker to modify the content of any post or page on a WordPress website. As of this morning, over 1.9 million domains had been defaced. At last report, this exploit had been targeted by at least 20 malicious hacker groups engaging in a sort of turf way.

The source of the vulnerability

The vulnerability is in the REST application programming interface (API) enabling hackers to attack unpatched WordPress sites by creating a simple HTTP request. This enables them to bypass authentication systems on WordPress sites and then edit the content and titles of web pages using WordPress versions 4.7.0 and 4.7.1.

Quick to exploit vulnerabilities, there has been a surge in attacks and WordPress site defacements by hacking groups. Experts say that the surge is a result of hacking groups competing for bragging rights.

Defacements are just the beginning

According to Daniel Cid, founder of Sucuri Security, defacements are just the first round of attacks from hackers seeking to exploit vulnerable WordPress websites. “Defacements don’t offer the economic returns, so that will likely die soon. What will remain are attempts to execute commands (RCE) as it gives the attackers full control of a website. This will allow them to monetize their hack through spam SEO / affiliate link / ad injections”, he says.

Attacks that seek to monetize a hack are starting to emerge and this is likely to continue for the coming days, weeks and possibly months. Attacks will continue as long as there are vulnerable WordPress websites.

For those sites that have not yet upgraded to the latest version of WordPress 4.7.2, it is strongly recommended to do so as your site will be vulnerable to attack.

The consequences of a hacked site

The consequences to an attacked site include:

  • Possible suspension of your website from Google search results
  • Loss of trust by your regular users
  • Possible data breaches
  • Loss of search engine rankings, traffic, leads and possibly sales
  • A large expense to clean up your website

Contact us if you need help with security for your WordPress website. We are also launching a WordPress maintenance service to manage these exact issues so business owners can focus on doing what they do best, running their business.

Please check back in the next day or two

2 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *