Huge vulnerability in Elementor Website Builder

bartosimpsonio

Elite Member
Executive VIP
Jr. VIP
Joined
Mar 21, 2013
Messages
24,764
Reaction score
31,552
https://thehackernews.com/2022/04/critical-rce-flaw-reported-in-wordpress.html
I've posted about this on several threads. There's no real reason to be using heavy plugins on your WP installation in this day and age.

HTML and CSS are commoddities now. You no longer need to pay thousands for a designer to build a site.

Anyway, if you use this plugin, get patched ASAP. It's a bad security flaw.
 
It's already been fixed with the latest updates.

Anyway, any plugin seems to have problems once in a while that doesn't mean we should stop using plugins anymore.
 
  • Like
Reactions: Kyz
The content builder is a bit slow. better hire a basic developer to do this. But if we don't have time and don't have funds, then go for this. But we have faced problems with caching issues. Like we updated a page, that's okay, but after 1 hour or 24 hours, that undoes!
 
Yup, all my websites got hacked.

If you ask me, it was clearly intentional. 5 millions installs premium pluging don't get such severe exploit by coincidence
 
I updated few minutes after ive got email, everything looks ok.
Check your links, especially affiliate or CPA content lockers. Even multiple times, once ive got similiar malware that replaced locker with same copy every 10th click...
 
If you ask me, it was clearly intentional. 5 millions installs premium pluging don't get such severe exploit by coincidence
You nailed it. That's why I always tell people to stay away from Wordpress.
 
You nailed it. That's why I always tell people to stay away from Wordpress.

Actually, quite the opposite. No other system in the world has so much eyes checking their code. It took few hours to find out the vulnerability. If this happened in any closed system, the exploit would stay for much longer if it even found out.

This is why I advice everyone to use Wordpress!
 
A member messaged me how to protect themselves from such hacks.. I think the reply would benefit anyone reading the thread, so, here it's.
========================
As a matter of fact I am prefessional ethical hacker myself.. so it was okay.

The good news, its really simple to prevent hacking damage.

There are two main ways to get hacked other than skids bruteforce and these basic stuffs.

1 - you upload nulled plugin which contains edited code of the plugin which gives the plugin provider control over the website

2 - Someone finds an exploit in the original code of thw plugin. Unfortunately, for really famous plugins its likely intentional.

The first reason, its really easy to prevent. Download plugin even nulled ones from good resources. Like famous forums where the cracker is a forum member. Or famous websites where the owner is reputable.

In forums they earn money from memberships and for reputable websites, they earn from ads.

As for second reason, you can't prevent the hack because like I said, its reputable plugin.. elementor, or slider revolution for example.

The easiest way to overcome Any hacking no matter what, is to have regular daily backup for the last 7 days at least. So, if you are hacked, just restore the older backup and you are done (Y). Simple and easy.

If you have really sensitive website, subscribe to sucuri, their firewall and file channges monitoring is really powerful.

Another simple method would be don't set auto update for plugins, and check sucuri blogs or any volunerability monitoring website if the new update is safe. It takes 2 days to find out if there is some exploit which makes wordpress the most powerful cms unlike gurus want you to think.

Finally, don't waste your time on any defense plugin, for exploit hacking they are worthless.

Pro Tip, 99,99% of hacking methods include some code change, or file edits. So, even if you got hacked, just find file changes on your server and remove it.

To Summarise

- Interval backup to remote drive is a must and most hosting provider provide this service btw. Or you can use any backup plugin. Be cautious, back up plugins usually backup wp-content folder only. While malicious codes are usually in the main folder.

So, its always better to backup the whole website including main wordpress files.

Or if you back up the wp-content, then make fresh install for the wordpress core to removd any malicious code hidden there.

- Don't upload any php code from some shady source

And this is it.
 
Last edited:
A member messaged me how to protect themselves from such hacks.. I think the reply would benefit anyone reading the thread, so, here it's.
========================
As a matter of fact I am prefessional ethical hacker myself.. so it was okay.

The good news, its really simple to prevent hacking damage.

There are two main ways to get hacked other than skids bruteforce and these basic stuffs.

1 - you upload nulled plugin which contains edited code of the plugin which gives the plugin provider control over the website

2 - Someone finds an exploit in the original code of thw plugin. Unfortunately, for really famous plugins its likely intentional.

The first reason, its really easy to prevent. Download plugin even nulled ones from good resources. Like famous forums where the cracker is a forum member. Or famous websites where the owner is reputable.

In forums they earn money from memberships and for reputable websites, they earn from ads.

As for second reason, you can't prevent the hack because like I said, its reputable plugin.. elementor, or slider revolution for example.

The easiest way to overcome Any hacking no matter what, is to have regular daily backup for the last 7 days at least. So, if you are hacked, just restore the older backup and you are done (Y). Simple and easy.

If you have really sensitive website, subscribe to sucuri, their firewall and file channges monitoring is really powerful.

Another simple method would be don't set auto update for plugins, and check sucuri blogs or any volunerability monitoring website if the new update is safe. It takes 2 days to find out if there is some exploit which makes wordpress the most powerful cms unlike gurus want you to think.

Finally, don't waste your time on any defense plugin, for exploit hacking they are worthless.

Pro Tip, 99,99% of hacking methods include some code change, or file edits. So, even if you got hacked, just find file changes on your server and remove it.

To Summarise

- Interval backup to remote drive is a must and most hosting provider provide this service btw. Or you can use any backup plugin. Be cautious, back up plugins usually backup wp-content folder only. While malicious codes are usually in the main folder.

So, its always better to backup the whole website including main wordpress files.

Or if you back up the wp-content, then make fresh install for the wordpress core to removd any malicious code hidden there.

- Don't upload any php code from some shady source

And this is it.
Good info but this is about an exploit on a specific plugin
 
Good info but this is about an exploit on a specific plugin

No, this would work with any type of any exploit. Or to deal with any hacking damage to be more specific
 
INMHO, too many websites are relying on Elementor. It's a crap plugin, a lot of bugs, slow loading speed, and so on. I've used it only a couple of times and was enough to ditch it for good.
 
If your IP is static restrict login to your IP only via htacccess. This helps a lot.
 
If your IP is static restrict login to your IP only via htacccess. This helps a lot.

For most severe exploits, it doesn't matter as you execute php commands as server owner.
 
Yup, all my websites got hacked.

If you ask me, it was clearly intentional. 5 millions installs premium pluging don't get such severe exploit by coincidence
So the developers are behind this?
 
INMHO, too many websites are relying on Elementor. It's a crap plugin, a lot of bugs, slow loading speed, and so on. I've used it only a couple of times and was enough to ditch it for good.
What do you recommend?
 
WordPress is adding page builder functionality to their core features. It's better to use WordPress blocks or GenerateBlocks (free version) instead of Elementor.
 
RCE flaw is not easy to find and exploit. But depends on the person who found it whether he uses for personal benefit or not.
 
Back
Top