Attackers exploit old WordPress to inject sites with code enabling site redirection, takeover
Attackers have exploited an old WordPress vulnerability to infect more than one thousand websites with malware capable of injecting malvertising and even creating a rogue admin user with full access privileges, according to researchers.
The exploited flaw is specifically found in outdated versions of the WordPress tagDiv Newspaper and Newsmag themes, according to a Dec. 14 blog post by Sucuri security analyst Douglas Santos. (Sucuri explains the vulnerability in further detail in an older report here.)
"Unfortunately, since this infection is related to a software vulnerability, strong passwords and security plugins will not protect you," writes Santos, noting that the malicious javascript can be found in a WordPress site's theme options.