Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware
ID: 0550bd64-d0cd-5395-b8c6-149e6aeef222
STIX ID: report--0550bd64-d0cd-5395-b8c6-149e6aeef222
Feed Name: Bleeping Computer
Attackers are actively exploiting CVE-2023-6000 (a stored XSS in Popup Builder ≤4.2.3) to inject malicious JavaScript/CSS into the Popup Builder custom sections and wp_postmeta on WordPress sites, redirecting visitors to phishing/malware destinations; Sucuri and PublicWWW report thousands of infections (Sucuri: ~1,170; PublicWWW: ~3,329), observed domains include ttincoming.traveltraffic.cc and host.cloudsonicwave.com, and remediation includes upgrading Popup Builder to 4.2.7, blocking the malicious domains, removing injected entries, and scanning for backdoors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
