<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wordpress Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/wordpress/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Tue, 04 Jul 2023 04:01:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</title>
		<link>https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/</link>
		
		<dc:creator><![CDATA[Anubhav]]></dc:creator>
		<pubDate>Tue, 04 Jul 2023 03:59:29 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=548814</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg?x96852" class="webfeedsFeaturedVisual wp-post-image" alt="Wordpress" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 300px) 100vw, 300px" /><p>In a shocking revelation, renowned security company Wordfence has recently uncovered a critical zero-day vulnerability in the widely used &#8220;user login system&#8221; plug-in, Ultimate Member, on the WordPress blogging platform. This vulnerability allows hackers to exploit their accounts and gain elevated administrative rights, effectively granting them full control over targeted websites. 200,000 websites have used [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/">Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg?x96852" class="webfeedsFeaturedVisual wp-post-image" alt="Wordpress" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 300px) 100vw, 300px" />
<p>In a shocking revelation, renowned security company Wordfence has recently uncovered a critical zero-day vulnerability in the widely used &#8220;user login system&#8221; plug-in, Ultimate Member, on the <a href="http://gizmochina.com/tag/wordpress">WordPress</a> blogging platform. This vulnerability allows hackers to exploit their accounts and gain elevated administrative rights, effectively granting them full control over targeted websites.</p>



<h3>200,000 websites have used the plugin until now</h3>



<p>The security flaw, identified as CVE-2023-3460, has been assigned a risk score of 9.8, indicating its severity. Through this vulnerability, cybercriminals can circumvent the plug-in&#8217;s built-in security measures, enabling them to manipulate the wp_capabilities configuration data of user accounts. By setting up their own accounts as administrators, hackers can assume complete control of compromised websites.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="683" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg?x96852" alt="Wordpress" class="wp-image-548815" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>The plug-in&#8217;s developer has responded swiftly to address the issue. On June 26, they released Ultimate Member version 2.6.3, which provided partial mitigation against the vulnerability. Subsequently, on July 1, version 2.6.7 was released, offering a complete fix for the security flaw.</p>



<p>Disturbingly, it has come to light that over 200,000 WordPress websites have incorporated the Ultimate Member plug-in. Given the high number of installations and the potential delay in updating the plug-in due to inadequate information dissemination, these websites remain exceptionally vulnerable to exploitation by malicious actors.</p>



<p>Web administrators and website owners are strongly advised to take immediate action by updating their Ultimate Member plug-in to the latest version, 2.6.7, to safeguard their websites against potential attacks. Additionally, it is crucial to remain vigilant and monitor any suspicious activity or unauthorized access attempts.</p>



<p>Experts emphasize the significance of promptly addressing software vulnerabilities and staying up-to-date with the latest security patches. Regularly updating plug-ins and software is an essential practice that ensures website integrity and safeguards against emerging <a href="http://gizmochina.com/tag/cyber-threats">cyber threats</a>.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/04/07/twitter-api-shutdown-chaos-developers/">Twitter’s API Shutdown Causes Chaos for Developers</a></li><li><a href="https://www.gizmochina.com/2021/11/12/xiaomi-leads-in-phone-sales-during-this-years-11-11-shopping-festival-apple-in-second/">Xiaomi leads in phone sales during this year’s 11.11 shopping festival, Apple in second</a></li><li><a href="https://www.gizmochina.com/guides/best-ultra-budget-smartphones-of-2023/">Best Ultra Budget Smartphones of 2023</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="HHOLOVE O Sitter Review: The first and the Best companion AI robot for Cats" width="696" height="392" src="https://www.youtube.com/embed/WcMjsjKRai8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.itworldcanada.com/article/cyber-security-today-july-3-2023-the-latest-ransomware-news-a-warning-to-wordpress-ultimate-member-administrators-and-more/542206">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/">Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 27/31 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 14/23 queries in 0.007 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-10-01 18:05:58 by W3 Total Cache
-->