Another top WordPress plugin exploited — hackers target credit card details, here's what you need to know

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg
  • Hackers are exploiting a critical flaw in the Funnel Builder plugin to inject credit card skimmers into checkout pages
  • FunnelKit released a patched version, but more than half of active sites remain on older, vulnerable builds
  • Stolen payment data is being monetized through dark web sales and fraudulent ad purchases

Hackers are exploiting a critical vulnerability in a popular WordPress plugin to steal credit card information from people making online purchases.

Security researchers Sansec said they recently spotted an active campaign targeting websites running the Funnel Builder plugin, which is apparently active on more than 40,000 ecommerce websites, letting businesses create sales funnels, landing pages, optimized checkout flows, upsells, and lead-generation campaigns, all without any coding.

Sansec found it carried a critical-severity vulnerability (no CVE yet), that allows threat actors to add malicious JavaScript snippets into WooCommerce checkout pages, without authentication. According to the researchers, someone used it to add...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

http://www.techmeme.com/img/techmeme_sq328.png

GitHub says it's investigating “unauthorized access” to its internal repositories, and there's no proof of customer data outside its repositories being impacted

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data