· Design My Website · Security  · 1 min read

1 Million WordPress sites are affected by this!

“On August 3, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for two vulnerabilities we discovered in the Gutenberg Template Library & Redux Framework plugin, which is installed on over 1 million WordPress sites. One vulnerability allowed users with lower permissions,

“On August 3, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for two vulnerabilities we discovered in the Gutenberg Template Library & Redux Framework plugin, which is installed on over 1 million WordPress sites. One vulnerability allowed users with lower permissions,

“On August 3, 2021, the Wordfence Threat Intelligence team initiated the disclosure process for two vulnerabilities we discovered in the Gutenberg Template Library & Redux Framework plugin, which is installed on over 1 million WordPress sites. One vulnerability allowed users with lower permissions, such as contributors, to install and activate arbitrary plugins and delete any post or page via the REST API. A second vulnerability allowed unauthenticated attackers to access potentially sensitive information about a site’s configuration.

The plugin’s publisher, Redux.io, replied almost immediately to our initial contact and we provided full disclosure the same day, on August 3, 2021. A patched version of the plugin, 4.2.13, was released on August 11, 2021.

Wordfence Premium users received a firewall rule to protect against the vulnerability targeting the REST API on August 3, 2021. Sites still running the free version of Wordfence will receive the same protection after 30 days, on September 2, 2021.” Source: Wordfence

Find out more about this vulnerability and how you can use Wordfence to protect your website.

All of the Design My Website maintenance plans come with a free install of Wordfence.

Contact us today

    Share:
    Back to Blog

    Related Posts

    View All Posts »

    Website Security: Protecting Your Site and User Data

    Now, I know what you’re thinking. Security can be about as exciting as watching paint dry, but trust me, it’s essential. Picture this: You’ve poured your heart and soul into creating a stunning website, and your users trust you with their precious data. It’s your responsibility to protect it like a

    WordPress Security Update 5.8.3 – Everything you need to know

    As always, because this latest update is a security update, we recommend all WordPress users to update to this latest version. The next major release will be WordPress 5.9. WordPress 5.9 is due for release in the last week on January 2022. Stay tuned for updates on 5.9. You can update to 5.8.3 by go