{"id":69581,"date":"2020-02-20T20:42:04","date_gmt":"2020-02-20T17:42:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok"},"modified":"2020-03-03T16:11:07","modified_gmt":"2020-03-03T13:11:07","slug":"uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","title":{"rendered":"Sicherheitsanf\u00e4lligkeiten in WordPress-Plugins mit mehr als einer Million Installationen.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sicherheitsexperten von Wordfence und WebARX haben mehrere schwerwiegende Sicherheitsl\u00fccken in f\u00fcnf Plugins f\u00fcr das Content Management System WordPress entdeckt, die insgesamt mehr als eine Million Installationen haben.<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/improper-access-controls-in-gdpr-cookie-consent-plugin\/\">Sicherheitsanf\u00e4lligkeit<\/a><\/noindex> im Plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/cookie-law-info\/\">GDPR Cookie Consent<\/a><\/noindex>, das \u00fcber 700.000 Installationen verf\u00fcgt. Der Schweregrad des Problems wurde mit 9 von 10 (CVSS) bewertet. Die Schwachstelle erm\u00f6glicht es einem authentifizierten Benutzer mit den Rechten eines Abonnenten, jede Seite der Website zu l\u00f6schen oder zu verbergen (indem er den Status auf nicht ver\u00f6ffentlichten Entwurf \u00e4ndert) sowie seinen eigenen Inhalt auf den Seiten anzuzeigen.<br \/>\nSicherheitsanf\u00e4lligkeit <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset\/2241572\/\">die Schwachstelle<\/a><\/noindex> in der Version 1.8.3.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/critical-issue-in-themegrill-demo-importer\/\">Sicherheitsanf\u00e4lligkeit<\/a><\/noindex> im Plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/themegrill-demo-importer\/\">ThemeGrill Demo Importer<\/a><\/noindex>, mit mehr als 200.000 Installationen (nach dokumentierten Angriffen auf Websites, nach denen die Zahl der Installationen bereits auf 100.000 gesenkt wurde). Die Schwachstelle erm\u00f6glicht es einem nicht authentifizierten Besucher, den Inhalt der Datenbank der Website zu l\u00f6schen und die Datenbank in den Zustand einer frischen Installation zur\u00fcckzusetzen. Ist in der Datenbank ein Benutzer mit dem Namen admin vorhanden, so erm\u00f6glicht die Schwachstelle zudem den vollst\u00e4ndigen Zugriff auf die Website. Die Schwachstelle wird durch einen Fehler beim Versuch verursacht, einen Benutzer zu authentifizieren, der privilegierte Befehle \u00fcber das Skript \/wp-admin\/admin-ajax.php senden m\u00f6chte. Das Problem wurde in Version 1.6.2 behoben.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/zero-day-vulnerability-in-themerex-addons-plugin-exploited-in-the-wild\/\">Sicherheitsanf\u00e4lligkeit<\/a><\/noindex> im Plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/themerex.net\/wp\/download_plugins\/themerex-addons\/\">ThemeREX Addons<\/a><\/noindex>, der auf 44.000 Websites verwendet wird. Der Schwachstelle wurde ein Risikograd von 9,8 von 10 zugewiesen. Die Schwachstelle erlaubt es einem nicht authentifizierten Benutzer, seinen PHP-Code auf dem Server auszuf\u00fchren und das Administrator-Konto der Website durch das Senden einer speziellen Anfrage \u00fcber die REST-API zu \u00fcbernehmen.<br \/>\n In der Community wurden bereits F\u00e4lle von Ausnutzung der Schwachstelle dokumentiert, jedoch steht das Update mit der Behebung bisher nicht zur Verf\u00fcgung. Den Benutzern wird geraten, dieses Plugin so schnell wie m\u00f6glich zu entfernen.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/vulnerability-in-wpcentral-plugin-leads-to-privilege-escalation\/\">Sicherheitsanf\u00e4lligkeit<\/a><\/noindex> im Plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wp-central\/\">wpCentral<\/a><\/noindex>, mit 60.000 Installationen. Das Problem wurde mit einem Gef\u00e4hrdungsgrad von 8,8 von 10 bewertet. Die Schwachstelle erm\u00f6glicht es jedem authentifizierten Benutzer, einschlie\u00dflich Abonnenten, seine Berechtigungen auf Administratorrechte zu erh\u00f6hen oder Zugriff auf das wpCentral-Dashboard zu erhalten. Das Problem wurde in Version 1.5.1 behoben.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/critical-vulnerability-in-profile-builder-plugin-allowed-site-takeover\/\">Sicherheitsanf\u00e4lligkeit<\/a><\/noindex> im Plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/profile-builder\/\">Profile Builder<\/a><\/noindex>, mit etwa 65.000 Installationen. Das Problem wurde mit einem Gef\u00e4hrdungsgrad von 10 von 10 eingestuft. Die Schwachstelle erlaubt es einem nicht authentifizierten Benutzer, ein Konto mit Administratorrechten zu erstellen (das Plugin erm\u00f6glicht die Erstellung von Registrierungsformularen, und der Benutzer kann einfach ein zus\u00e4tzliches Feld mit der Benutzerrolle \u00fcbermitteln und ihm Administratorrechte zuweisen). Das Problem wurde in Version 3.1.1 behoben.\n<\/ul>\n<p>Dar\u00fcber hinaus kann die <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.prevailion.com\/2020\/02\/phps-labyrinth-weaponized-wordpress.html\">Identifizierung<\/a><\/noindex> Netzwerke zur Verbreitung von Trojaner-Plugins und WordPress-Themes. Angreifer haben raubkopierte Versionen kostenpflichtiger Plugins auf gef\u00e4lschten Katalog-Webseiten ver\u00f6ffentlicht, nachdem sie zuvor einen Backdoor installiert hatten, um aus der Ferne auf die Server zuzugreifen und Befehle von einem Kontrollserver zu laden. Nach der Aktivierung wurde der sch\u00e4dliche Code genutzt, um sch\u00e4dliche oder irref\u00fchrende Werbung einzuschleusen (zum Beispiel Warnungen, die zur Installation eines Antivirusprogramms oder zur Aktualisierung des Browsers auffordern), sowie zur Suchmaschinenoptimierung zur F\u00f6rderung von Webseiten, die sch\u00e4dliche Plugins verbreiten. Vorl\u00e4ufigen Daten zufolge wurden durch diese Plugins mehr als 20.000 Webseiten kompromittiert. Zu den Opfern z\u00e4hlen eine dezentrale Mining-Plattform, eine Handelsfirma, eine Bank, mehrere gro\u00dfe Unternehmen, ein Entwickler von Zahlungsl\u00f6sungen mit Kreditkarten und IT-Unternehmen.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52398\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 GDPR Cookie Consent, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 700 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9 \u0438\u0437 10 (CVSS). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0430 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438\u043b\u0438 \u0441\u043a\u0440\u044b\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-69581","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 GDPR Cookie Consent, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 700 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9 \u0438\u0437 10 (CVSS). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0430 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438\u043b\u0438 \u0441\u043a\u0440\u044b\u0442\u044c\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 GDPR Cookie Consent, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 700 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9 \u0438\u0437 10 (CVSS). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0430 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438\u043b\u0438 \u0441\u043a\u0440\u044b\u0442\u044c\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-20T17:42:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:11:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Schwachstellen in WordPress-Plugins mit \u00fcber einer Million Installationen | ProHoster","description":"Sicherheitsforscher von Wordfence und WebARX haben mehrere kritische Schwachstellen in f\u00fcnf Plugins f\u00fcr das Content-Management-System WordPress entdeckt, die insgesamt \u00fcber eine Million Installationen z\u00e4hlen. Eine gef\u00e4hrliche Schwachstelle im Plugin GDPR Cookie Consent hat mehr als 700.000 Installationen. Diese Schwachstelle wurde mit einem Risikolevel von 9 von 10 (CVSS) eingestuft. Sie erm\u00f6glicht es authentifizierten Nutzern mit Abonnentenrechten, Inhalte zu l\u00f6schen oder zu verstecken.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 GDPR Cookie Consent, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 700 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9 \u0438\u0437 10 (CVSS). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0430 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438\u043b\u0438 \u0441\u043a\u0440\u044b\u0442\u044c","og:url":"https:\/\/prohoster.info\/de\/blog\/novosti-interneta\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-20T17:42:04+00:00","article:modified_time":"2020-03-03T13:11:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"69581","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:20:24","updated":"2022-10-05 19:44:59"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/69581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=69581"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/69581\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=69581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=69581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=69581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}