19 Sep 2022

Wordfence and Security Journalists Are Again Creating FUD About the Security of WordPress Websites

Last week numerous news outlets ran scary sounding stories about a claimed security issue in a WordPress plugin. Here are some of the headlines of stories that were included in Google News:

  • WordPress zero-day vulnerability compromised more than 280000 websites: Researchers
  • 280000 WordPress sites hacked by exploitation of CVE-2022-3180 – Web Hosting
  • Shocking Cyberattack by Hackers on 280000 WordPress Sites
  • Shocking cyberattack! 280000 WordPress sites attacked by hackers
  • Over 280,000 WordPress Sites Attacked Using WPGateway Plugin Zero-Day Vulnerability
  • Zero-day in WPGateway WordPress plugin actively exploited in attacks
  • WordPress Plugin Vulnerability Abused in Zero-Day Exploit
  • WordPress zero-day vulnerability leads to 4.6 million attempted attacks on websites
  • WordPress plugin vulnerability leaves sites open to total takeover
  • Over 280000 WordPress sites may have been hijacked by zero-day hiding in popular plugin

The last one of those was from a TechRadar story written by Sead Fadilpašić. The sub-headline of the story was: [Read more]