WordPress users warned of plugin flaw being exploited in porn spam attack
Tens of thousands of websites running WordPress are thought to have been put at risk from a vulnerability that hackers have been actively exploiting to inject pornographic spam messages.
The problem lies in versions of a WordPress plugin called WP Mobile Detector\, which attempts to detect if visitors are browsing a website on a mobile device, and display an appropriate theme for the platform rather than one designed for desktop browsers.
As security researchers at Sucuri report, the zero-day vulnerability in WP Mobile Detector was disclosed by the Plugin Vulnerabilities team at the end of May, a couple of days after the developers were informed of the problem. Attackers were able to exploit a flaw in the plugin’s code that failed to properly validate and sanitise web input from untrusted sources, allowing anyone to feed malicious PHP code into a vulnerable website.