Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
黑客正在利用近期修复的 WordPress 漏洞,数百万网站面临风险
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. 据多家网络安全公司称,黑客正在入侵运行易受攻击版本 WordPress 博客软件的网站。据周一的一项估计,存在漏洞的 WordPress 网站数量高达数千万。
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. 上周,WordPress 修复了两个关键安全漏洞,并敦促在其网站上运行该软件的用户“立即”进行更新。由于漏洞极其严重,WordPress 在可能的情况下启用了强制更新。
Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress. 此后,网络安全公司 Patchstack、Hexastrike 和 WatchTowr 均发出警告称,黑客正在现实环境中利用这些漏洞,这意味着他们正在接管那些仍在使用易受攻击版本 WordPress 的网站。
It’s unclear how many WordPress-powered websites on the internet are at risk, but it’s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don’t reflect websites that have recently been patched. 目前尚不清楚互联网上有多少 WordPress 驱动的网站面临风险,但可以进行一些合理的推测。受影响的 WordPress 版本为 6.9.0 至 6.9.4 以及 7.0.0 至 7.0.1。根据 WordPress 的官方统计,有超过 4 亿个网站运行这些存在缺陷的版本,尽管这些统计数据可能并未反映出近期已完成修复的网站。
Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. 网络安全顾问 Daniel Card 告诉 TechCrunch,他抽样调查了约 3,500 个 WordPress 网站,估计其中不到 15% 存在漏洞。将 Card 的预测应用于互联网上 WordPress 网站的总数,受影响的网站总数仍可能在 9000 万左右。
The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked. 该研究人员认为,WordPress 推送自动更新、Cloudflare 拦截针对易受攻击网站的攻击,以及网站使用网络防火墙等安全保护措施,是目前被黑客攻击的网站数量有限的原因。
WordPress.org, the project that develops WordPress’ open source code, did not immediately respond to a request for comment. Megan Fox, a spokesperson for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.” 负责开发 WordPress 开源代码的 WordPress.org 项目组没有立即回应置评请求。运营 WordPress.com 并为该开源项目做出贡献的 Automattic 公司发言人 Megan Fox 对 TechCrunch 表示:“所有由 Automattic 托管的网站,包括 WordPress.com、Pressable、WPVIP 和 WP.cloud 合作伙伴,在漏洞发布前就已经得到了保护。当代码更新发布时,我们立即在数百万个网站上进行了部署。”
One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites. 其中一个关键的 WordPress 漏洞是由网络安全公司 Searchlight Cyber 的 Adam Kues 发现并报告的,该公司将其命名为 WP2Shell。配合另一个漏洞,黑客可以完全远程控制易受攻击的网站。