Three WordPress Plugins Have Security Vulnerabilities Allowing Malicious Command File Injection
Malicious campaigns are exploiting high-severity XSS vulnerabilities in three WordPress plugins to inject malicious command files and backdoors into websites.

According to Fastly, Security Vulnerabilities in Three WordPress Plugins Allow Injection of Malicious Scripts and Backdoors into Various Websites
According to Fastly, security vulnerabilities in three WordPress plugins are being used to inject malicious scripts and backdoors into various websites. These flaws can be exploited via XSS attacks, allowing attackers to create administrator accounts on WordPress, inject PHP backdoors into plugin and theme files, and place monitoring scripts to track infected targets. Fastly reports that there are a significant number of exploitation attempts.
One of these vulnerabilities (CVE-2024-2194) affects the WP Statistics plugin, which has over 600 active installations. The vulnerability impacts versions 14.5 and newer of the plugin, and it was disclosed in March of this year.
The second vulnerability (CVE-2023-6961) is related to the WP Meta SEO plugin in versions 4.5.12 and newer; the plugin has over 20,000 active installations. Attackers can exploit the flaw to create a 404 response by injecting a payload. When the page manager's browser loads the page, the script retrieves JavaScript code from a remote server and steals credentials if the victim is authenticated.
As part of the campaign, cybercriminals are also exploiting a vulnerability in the LiteSpeed Cache plugin (CVE-2023-40000) in versions 5.7.0.1 and newer. This plugin has over 5 million active installations.
Source: Vulnerabilities in Three WordPress Plugins Allow Injection of Malicious Scripts (itsecurity.pt)