Без рубрики

Popular WordPress page builder, Elementor has issued an update to patch a vulnerability called an Authenticated Reflected XSS. This kind of vulnerability allows a hacker to run a script from another site and do things such as steal login credentials.

The vulnerability involves causing a script to be loaded to the vulnerable site (for example through a search box), creating a URL that when followed will execute the script (that is hosted on another site). The hacker then sends a link to someone whose credentials could then be stolen by the hacker.

According to the WordPress Vulnerability Database, the proof of concept is being hidden until February 12th to give users time to update.

The website security company site that discovered the vulnerability (Impenetrable.tech) have published a walk-through of how they discovered the security flaw.

Screenshot from security company that discovered the vulnerability

Free Google Ads report finds improvements in 60 seconds
Based on actual data from your own campaigns.

Once they discovered the vulnerability they contacted the publishers of the Elementor Page Builder plugin and the publishers updated it right away.

Only after Elementor was patched did the security site publish an account of the vulnerability.

This vulnerability affects versions 2.8.4 and older. It is advisable to log into your WordPress website and update your site if you use the Elementor Page Builder plugin. The most current version of Elementor Page Builder is 2.8.5.

Once you sign into your WordPress account there should be an update link from the admin navigation ribbon at the top of the page, or you can access your updates page from the link in the admin sidebar to view all available updates.

30.01.2020
elementor

Elementor Page Builder Plugin Vulnerability

Popular WordPress page builder, Elementor has issued an update to patch a vulnerability called an Authenticated Reflected XSS. This kind of vulnerability allows a hacker to […]
04.12.2019
0UQPSQK9OPDy4_PQJYthSesPqZLcUcEYM6opBfPDSx4

12 Ways to Build a Winning SEO Strategy on a Small Budget

We’ve read the blogs, we’ve heard the talks, we’ve seen the case studies. Big brands are winning at SEO. They’ve got: A team of experts working […]
07.10.2019
microservices_minitature_figurines_service_repair_circuit_board_thinkstock_87524273-100624778-large

What are microservices? Your next software architecture

Nearly every computer system performs multiple tasks using shared resources, and one of the questions of computer programming is how closely the bits of code that […]
24.09.2019
how-to-block-google-760x400

John Mueller Answers How to Block Google from a Staging Site

In a Webmaster Hangout, Google’s John Mueller answered the question of how to stop Google from crawling and indexing a staging server. What is a Staging […]
28.08.2019
cc152f1b-4e95-4412-8e6f-7ed346d5cbbf-760x400

Study Finds the Structure of Most Blogs May Be Hurting Search Rankings

A recent study on blog structure finds most blogs are making a critical mistake that could impact rankings. The problem is related to link depth, which […]
20.08.2019
bdbce878-9323-4354-bc61-fef97352a057-760x400

Google’s Mobile-Friendly Test Doesn’t Follow Robots.txt Rules

Google’s John Mueller recently advised the company’s mobile-friendly test doesn’t follow the rules written in robots.txt files. This topic came up in a Google Webmaster Central […]
13.08.2019
5-tips-to-improve-your-regional-seo-strategy-760x400

5 Tips to Improve Your Regional SEO Strategy

For some businesses, ranking for a larger region may make more sense than optimizing for a hyperlocal approach. This is especially true for service area businesses […]
23.07.2019
graffiti-free-font-21

The 15 Best Free Graffiti Fonts

Are you looking for a unique font for your movie poster design or a magazine cover? Then consider a graffiti font. These fonts often feature a unique design […]
10.07.2019
web-design-practices-that-frustrate-seo-760x400

Web Design Practices That Frustrate SEO Pros

What web design practices interfere with SEO? Do web developers and digital marketers clash over webpage design decisions? What issues face today’s website management teams? If […]
24.06.2019
how-to-manage-maximize-visual-content-creation-on-a-large-scale-760x400

How to Manage & Maximize Visual Content Creation on a Large Scale

Producing content is a challenge for businesses of all sizes – but especially for large organizations. With so many moving parts, enterprises must find a way […]