Pharma Hack MAY 2022
WP/Woo Security Exploits for SEO/DDoS
Be informed about the latest WP Security Exploits for SEO gains and DoS/DDoS remote controls, identified and reported publicly. With Pharma Hack MAY 2022 the consequences of a hack are ugly. You will experience major backlash on your WordPress domain, costly damage control/recovery, immediate revenue loss with long-term consequences. Consider our Pharma Hack audit.
An estimated 6.955.000+ active WordPress installations are susceptible to these attack types, considering only the publicly available numbers. It is a jaw-dropping +130% INCREASE compared to last month. The estimated number can double with versions already closed due to security concerns.
The following cases made headlines PUBLICLY in the Pharma Hack MAY 2022 category:
Hire security professionals to protect your WP/Woo from publicly reported cases of Pharma Hack MAY 2022 BEFORE IT’S TOO LATE! You will also protect your customers, your reputation and your online business!
- ThirstyAffiliates Affiliate Link Manager - Arbitrary Affiliate Links Creation
- ThirstyAffiliates Affiliate Link Manager - Unauthorised Image Upload + CSRF
- Active installations: 40.000+
- Weblizar Pin It Button On Image Hover And Post - Arbitrary Settings Update
- Active installations: 20,000+
- Cool Timeline - Arbitrary Plugin Activation
- Cool Timeline - Arbitrary Plugin Installation
- Active installations: 20,000+
- Ad Invalid Click Protector (AICP) - Cross-Site Request Forgery (CSRF)
- Ad Invalid Click Protector (AICP) - Reflected Cross-Site Scripting (XSS)
- Ad Invalid Click Protector (AICP) - Arbitrary Ban Deletion via CSRF
- Active installations: 20,000+
- Events Search For The Events Calendar - Arbitrary Plugin Activation
- Events Search For The Events Calendar - Arbitrary Plugin Installation
- Active installations: 2,000+
- Event Countdown For The Events Calendar - Arbitrary Plugin Activation
- Event Countdown For The Events Calendar - Arbitrary Plugin Installation
- Active installations: 3,000+
- Event Single Page Templates Addon For The Events Calendar - Arbitrary Plugin Activation
- Event Single Page Templates Addon For The Events Calendar - Arbitrary Plugin Installation
- Active installations: 3,000+
- Cryptocurrency Donation Box – Bitcoin & Crypto Donations - Arbitrary Plugin Installation
- Cryptocurrency Donation Box – Bitcoin & Crypto Donations - Arbitrary Plugin Activation
- Active installations: 5,000+
- Events Widgets For Elementor And The Events Calendar - Arbitrary Plugin Activation
- Events Widgets For Elementor And The Events Calendar - Arbitrary Plugin Installation
- Active installations: 5,000+
- Events Shortcodes For The Events Calendar - Arbitrary Plugin Activation
- Events Shortcodes For The Events Calendar - Arbitrary Plugin Installation
- Active installations: 10,000+
- Cryptocurrency Widgets – Price Ticker & Coins List - Arbitrary Plugin Activation
- Cryptocurrency Widgets – Price Ticker & Coins List - Arbitrary Plugin Installation
- Active installations: 10,000+
- Migration, Backup, Staging – WPvivid - Arbitrary File Read
- Active installations: 100,000+
- SiteGround Security - Authorization Weakness to Authentication Bypass via 2-Factor Authentication Back-up Codes
- SiteGround Security - Authentication Bypass via 2-Factor Authentication Setup
- Active installations: 400,000+
- WordPress Wbcom BuddyPress Hashtags - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: N/A
- BuddyPress Check-ins Pro - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: N/A
- BuddyPress Sticky Post - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: N/A
- Wbcom Designs – WordPress System Log - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Woo Document Preview - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Sitemap by click5 - Unauthenticated Arbitrary Options Update
- Active installations: 8,000+
- Woo Audio Preview - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Custom Font Uploader - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Custom Font Uploader - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Wbcom Designs BuddyPress Todo List - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Wbcom Designs – Private Community for BuddyPress - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 700+
- Wbcom Designs – BuddyPress Search - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Wbcom Designs – BuddyPress Member Reviews - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 800+
- Wbcom Designs – BuddyPress Job Manager - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 400+
- Wbcom Designs – BuddyPress Group Reviews - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Wbcom Designs – BuddyPress Create Group Type - Arbitrary Plugin Installation, Activation and Deactivation
- This plugin has been closed as of March 9, 2022 and is not available for download. This closure is temporary, pending a full review.
- Wbcom Designs – Check-ins for BuddyPress Activity - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 200+
- Wbcom Designs – BuddyPress Ads - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 100+
- Wbcom Designs – BuddyPress Activity Social Share - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 1,000+
- Wbcom Designs – BuddyPress Activity Filter - Arbitrary Plugin Installation, Activation and Deactivation
- Active installations: 1,000+
- Import WP – Import and Export WordPress data to XML or CSV files - Arbitrary File Upload vulnerability leading to Remote Code Execution (RCE)
- Active installations: 1,000+
- All In One WP Security & Firewall - Authenticated Arbitrary Redirect / Reflected XSS
- Active installations: 1+ million
- Cryptocurrency Widgets For Elementor - Arbitrary Plugin Activation
- Cryptocurrency Widgets For Elementor - Arbitrary Plugin Installation
- Active installations: 1,000+
- Elementor Website Builder - Arbitrary File Upload
- Active installations: 5+ million
- Fancy Product Designer - Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload
- Active installations: N/A
- MicroPayments – Paid Author Subscriptions, Content, Downloads, Membership - Arbitrary Settings Update via Cross-Site Request Forgery (CSRF)
- Active installations: 100+
- VikBooking Hotel Booking Engine & PMS - Arbitrary File Upload leading to RCE
- VikBooking Hotel Booking Engine & PMS - Sensitive Data Exposure
- Active installations: 3,000+
- Advanced uploader - Arbitrary File Upload
- This plugin has been closed as of March 28, 2022 and is not available for download. This closure is temporary, pending a full review.
- Rara One Click Demo Import - Cross-Site Request Forgery (CSRF) leads to Arbitrary File Upload
- Active installations: 40,000+
- Coru LFMember - Arbitrary Game Deletion/Activation via Cross-Site Request Forgery (CSRF)
- Coru LFMember - Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF)
- This plugin has been closed as of April 27, 2022 and is not available for download. This closure is temporary, pending a full review.
- WP-Invoice – Web Invoice and Billing - Arbitrary Settings Update via Cross-Site Request Forgery (CSRF)
- WP-Invoice – Web Invoice and Billing - Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF)
- This plugin has been closed as of April 27, 2022 and is not available for download. This closure is temporary, pending a full review.
- WP 2FA – Two-factor authentication for WordPress - Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR)
- Active installations: 20,000+
- WPQA Builder Plugin - Arbitrary Profile Picture Deletion via IDOR
- WPQA Builder Plugin - Private Message Disclosure via IDOR
- WPQA Builder Plugin - Stored Cross-Site Scripting via Profile fields
- Active installations: N/A
- AGIL (Automatic Grid Image Listing) - Arbitrary File Upload
- This plugin has been closed as of March 31, 2022 and is not available for download. This closure is temporary, pending a full review.
- All-in-One WP Migration - Directory Traversal to File Deletion on Windows Hosts
- Active installations: 4+ million
- WP 2FA – Two-factor authentication for WordPress - Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR)
- Active installations: 20,000+
- WPQA Builder Plugin - Arbitrary Profile Picture Deletion via IDOR
- WPQA Builder Plugin - Private Message Disclosure via IDOR
- WPQA Builder Plugin - Stored Cross-Site Scripting via Profile fields
- Active installations: N/A
- WP 2FA – Two-factor authentication for WordPress - Arbitrary 2FA Disabling via Insecure Direct Object References (IDOR)
- Active installations: 20,000+
- External Media without Import - Blind SSRF
- This plugin has been closed as of March 28, 2022 and is not available for download. This closure is temporary, pending a full review.
- HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics - Blind Server-Side Request Forgery (SSRF)
- Active installations: 200,000+
Get Healthy, Stay Healthy! A healthier online business starts today and it begins with your WP/Woo. Hire security experts to solve all your vulnerabilities created from Pharma Hack MAY 2022.
BRIEF: Pharma Hack MAY 2022 is an SEO spam attack type, where a legitimate website is used to sell illicit drugs. In this type of attack, hackers hijack websites, injects malware and uses that specific domain to sell illicit drugs like Viagra, Cialis, Levitra. This is where it started and got its name. Today, not just potency drugs are a drive. Anything that created interest from humans, but their local legislation failed to keep up with the latest trends are in this category. Consider this as a modern inquisition, where your domain is the heretic, spreading undesired ideology - sadly unknowingly.
Pharma Hack Explained
The Pharma Hack MAY 2022 exploits are used to insert rogue code in outdated versions of WordPress, themes and plugins. This new content inside existing pages and post are causing search engines to return ads for pharmaceutical products after a new indexation. The vulnerability is more of a spam menace than traditional malware but gives search engines enough reason to block the domain for distributing spam (NOT creating, JUST maintaining, harbouring, spreading).
Working parts of a Pharma Hack MAY 2022 include a backdoor in plugins, themes and databases. However, the exploits are often vicious variants of encrypted malicious injections hidden in databases and require a thorough clean-up process to fix the vulnerability. Nevertheless, you can easily prevent Pharma Hack by regularly updating your WordPress installations, themes, and plugins.
What is the impact of Pharma Hack MAY 2022?
The consequences of a hack are ugly. You will experience some major backlash on your WordPress domain such as:
- A marked drop in search engine rankings for the keywords you’re targeting;
- High bounce rates as visitors are redirected to different websites;
- Wasted SEO efforts in the future;
- SERP blacklist warnings on your website like:
-- This site may be hacked
-- Deceptive site ahead etc;
-- Hosting account suspensions;
-- Email providers blacklisting your domain;
-- High cleanup, recovery, damage control costs;
-- Major decline in your brand’s image, reputation.
What is Denial of Service (DoS)?
Perhaps the most dangerous of them all, Denial of Service (DoS) is used to overwhelm a specific domain's hosting resources (memory, CPU, bandwidth, etc). Denial of service is typically accomplished by flooding the targeted machine or resource with superfluous requests in an attempt to overload systems and prevent some or all legitimate requests from being fulfilled.
Hackers have compromised millions of websites and raked in millions by exploiting outdated and buggy versions of WordPress, themes, plugins and 3rd party connected software. Even the latest versions of WordPress software cannot comprehensively defend against high-profile DoS attacks, but will at least help you to avoid getting caught in the crossfire between financial institutions and sophisticated cybercriminals.
What is Distributed Denial of Service (DDoS)?
A distributed denial-of-service (DDoS) attack is one of the most powerful weapons on the internet. When you hear about a website being “brought down by hackers”, it generally means it has become a victim of a DDoS attack. In short, this means that hackers made that domain unavailable by flooding or crashing the website with too much traffic.
Although financially motivated cybercriminals are less likely to target small companies, they tend to compromise outdated vulnerable websites in creating botnet chains to attack large businesses. The primary way a DDoS is accomplished is through a network of remotely controlled, hacked domains. This is where small businesses come to the crossfire. These are often referred to as zombies, botnets or network of bots. These are used to flood a high profile target.
What is the impact of DoS/DDoS?
Starts with a slow website, with vital parts not working accordingly (checkout, orders/account registration, processing, dispatching). It peaks for a real visitor as page not available. When the entire server crashed, then the domain is unavailable. END GAME.
This is a costly thing to defend in a cloud environment, due to creating more and more servers to serve traffic spike, it burns your hosting budget for an entire year in a few hours. In classical hosting environments, using a single physical machine to host the domain is simply incapable of facing even the most simple, smallest DoS or DDoS attacks.
SOLVE TODAY any reported Pharma Hack MAY 2022 vulnerability! Do you suspect security / seo circumvention in your WordPress / WooCommerce?