• Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+
Precise Online ManagementPrecise Online Management
  • Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+

Another popular WordPress plugin has major exploit patched

Plugin Exploit

Another popular WordPress plugin has major exploit patched

February 26, 2019 News, Security

News Courtesy of ZDNet.com:

The vulnerability exploited in the attacks affects “WP Cost Estimation & Payment Forms Builder,” a commercial WordPress plugin for building e-commerce-centric forms that has been on sale on the CodeCanyon marketplace for the last five years.

In an interview with ZDNet, Defiant Threat Analyst Mikey Veenstra said hackers were using the hacked site they investigated to hijack incoming traffic and redirect it to other websites. He didn’t exclude the attackers abusing the backdoor for other nefarious activities later down the line.

All WP Cost Estimation versions before v9.644 are vulnerable to these attacks, according to Wordfence. The good news is that the developer fixed the bug with the release of v9.644 in October 2018, after one user complained about having their site hacked.

– Read Source Article

Ryan’s Take

This particular exploit really hits close to home. WP Cost Estimation & Payment Forms Builder is a premium plugin that I’ve been using on this site for over a year. It’s a fantastic plugin that has allowed me to customize packages for web design and SEO clients. Before you check, yes, I’m already updated to a secure version.

I’m usually pretty good at staying on top of theme and plugin updates. Since I bought it from CodeCanyon, I have a license that allows for easy updating. Unfortunately for people who bought the plugin on 3rd party websites or downloaded it illegally, you might be in for a rude awakening.

It’s hard to feel bad for these people. That’s the risk you run when not purchasing (or pirating) through the official developer. You also won’t get support from the developer either. So if you run into a problem, you’re on your own!

In this case, the developer has been very responsive to the few issues I’ve had and provided me with solutions to fix them. However, in my opinion, he should have made users aware of this major flaw through email. Instead, it looks like it is only casually mentioned in the changelog (and perhaps in CodeCanyon comments).

It sucks for the guy who had his website hacked which initially alerted the developer. That could’ve easily been this website. It’s hard to say whether my server’s anti-malware plugin would’ve caught it. However, since it relies on files being uploaded (which I do not ask for in this plugin’s settings), I suppose I would’ve been safe.

0 0 votes
Article Rating
Share
0

About Ryan Faucher

Owner-operator of Precise Online Management. I also manage Kettlebell Krusher, a website dedicated to all things kettlebell as well a blog for my weight loss progress.

Subscribe
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments

Categories

  • News
  • Niche Dreams
  • Reviews
  • Security
  • SEO
  • Tips

Recent Posts

  • 9 Benefits of Social Media for Your Organization
  • Advantages of Having Marketing Research Samples
  • Link Building Services: How To Find A Trustworthy Provider
  • SAS Affiliate Review and Tips for Affiliate Marketers
  • Comparison Of The Best Link Indexing Service Features & Benefits

Archives

  • January 2022
  • January 2021
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
Ready to get started? Pick and choose your website and / or SEO services Order Services

© 2025 · Precise Online Management, LLC.
This site is owned and operated by Ryan Faucher

  • Visit Us on Facebook
  • Visit Us On Google+
Prev Next
wpDiscuz
X
WEB DESIGN SPECIAL PRICING - Over 60% off design packages through Fiverr
See Details