Wordpress 0day xploit comment2shell - Not sure why so many people still on wordpress...

justmeseo

Power Member
Joined
Nov 16, 2017
Messages
682
Reaction score
488
This github went available not long ago, it has been updated just 12 hours ago https://github.com/DeathShotXD/Comment2Shell it targets most of the wordpress sites out there whatsout if you are in any of this versions.



WordPress BranchVulnerable VersionsFixed Version
7.17.17.1.1
7.07.0–7.0.47.0.5
6.96.9–6.9.76.9.8
6.86.8–6.8.86.8.9
6.76.7–6.7.76.7.8
6.66.6–6.6.76.6.8
6.56.5–6.5.106.5.11
6.46.4–6.4.106.4.11
6.36.3–6.3.106.3.11
6.26.2–6.2.116.2.12
6.16.1–6.1.126.1.13
6.06.0–6.0.146.0.15
5.95.9–5.9.165.9.17
5.85.8–5.8.155.8.16
5.75.7–5.7.175.7.18
5.65.6–5.6.195.6.20
5.55.5–5.5.205.5.21
5.45.4–5.4.215.4.22
5.35.3–5.3.235.3.24
5.25.2–5.2.265.2.27
5.15.1–5.1.245.1.25
5.05.0–5.0.275.0.28
4.94.9–4.9.314.9.32
4.84.8–4.8.304.8.31
4.74.7–4.7.354.7.36
 
thanks for moving the post to the right place.
 
Most people install WordPress and abandon the sites for several months without any maintenance. This exploit is going to be in News for some time.
 
Most people install WordPress and abandon the sites for several months without any maintenance. This exploit is going to be in News for some time.
I agree, everyday a new plugin, new theme with more defects.
 
If you update your WordPress site(s) often, there are small chances to get in trouble.
 
Not sure why so many people still on wordpress..
because most people are used to it, until something better comes it will keep being the most used CMS
 
If you update your WordPress site(s) often, there are small chances to get in trouble.
its true, the question is do everyone does that ?
because most people are used to it, until something better comes it will keep being the most used CMS
Indeed, I dont think nothing will be able to replace it.
 
This github went available not long ago, it has been updated just 12 hours ago https://github.com/DeathShotXD/Comment2Shell it targets most of the wordpress sites out there whatsout if you are in any of this versions.



WordPress BranchVulnerable VersionsFixed Version
7.17.17.1.1
7.07.0–7.0.47.0.5
6.96.9–6.9.76.9.8
6.86.8–6.8.86.8.9
6.76.7–6.7.76.7.8
6.66.6–6.6.76.6.8
6.56.5–6.5.106.5.11
6.46.4–6.4.106.4.11
6.36.3–6.3.106.3.11
6.26.2–6.2.116.2.12
6.16.1–6.1.126.1.13
6.06.0–6.0.146.0.15
5.95.9–5.9.165.9.17
5.85.8–5.8.155.8.16
5.75.7–5.7.175.7.18
5.65.6–5.6.195.6.20
5.55.5–5.5.205.5.21
5.45.4–5.4.215.4.22
5.35.3–5.3.235.3.24
5.25.2–5.2.265.2.27
5.15.1–5.1.245.1.25
5.05.0–5.0.275.0.28
4.94.9–4.9.314.9.32
4.84.8–4.8.304.8.31
4.74.7–4.7.354.7.36
yeah, good heads-up. Best thing is to keep wordpress , plugin and themes updated and double check if your version is actually affected.
 
yeah, good heads-up. Best thing is to keep wordpress , plugin and themes updated and double check if your version is actually affected.
Exactly, if you could only know how many people that I know got their sites hacked like that, the exploit is incredible and well thought.
 
The main move is updating to the latest version and keeping plugins/themes patched.

Most of these exploits hit outdated installs, so staying current and using basic security habits is usually enough to avoid getting caught.
 
Back
Top