[WARNING] WordPress Plugin Flaw Used for Malicious Redirects and Pop-Ups

Porthos

Well-Known Member
Reaction score
14,065
Location
San Antonio Tx
Hackers are currently attacking WordPress websites with outdated versions of the WP Live Chat Support plugin to redirect visitors to malicious locations or expose them to unwanted popups and fake subscriptions.

Earlier this month BleepingComputer reported that plugin versions before 8.0.7 are affected by a stored cross-site scripting (XSS) vulnerability that can be leveraged without authentication. This allows injecting malicious JavaScript on multiple pages of an affected website.

WP Live Chat Support has over 50,000 active installations at the time of writing and is intended as a free chat for engaging customers and increasing conversion rates.

https://www.bleepingcomputer.com/ne...law-used-for-malicious-redirects-and-pop-ups/
 
@Porthos Hate to tell you but the minute any code is able to give a popup though a add-blocker is going to be exploitable for example here Thesource and Walmart tech support online both can bounce the crap on pop-ups on you so I'm really not surprised.
 
Back
Top