• Economy
  • Investing
  • Editor’s Pick
  • Stock
Evil Shark Trades
Editor's Pick

Crypto Widget WordPress Plugin Flagged as “Critical” Cybersecurity Risk

by February 8, 2024
by February 8, 2024

A crypto widget plugin for web content management system WordPress was named as a “critical cybersecurity risk” yesterday.

A security bulletin released by the Cyber Security Agency of Singapore (CSA) noted that a plugin called “The Cryptocurrency Widgets – Price Ticker & Coins List” has been identified as a cybersecurity risk and could potentially be exploited to extract sensitive information.

The crypto widget obtained a base score of 9.8/10, placing it in the “critical” group of vulnerabilities the CSA uses to refer to vulnerabilities with a minimum score of 9/10.

The Crypto Widget Plugin’s Vulnerabilities


The National Vulnerability Database (NVD), the U.S. government repository for standards-based vulnerability management data, said that the WordPress crypto plugin is susceptible to SQL Injection through the ‘coinslist’ parameter in versions 2.0 to 2.6.5.

This vulnerability arose from insufficient escaping on the user-supplied parameter and inadequate preparation on the existing SQL query. It permitted the extraction of sensitive information from the database, enabling unauthenticated attackers to add additional structured language queries to the existing ones.

According to the security firm CVE Program, the widget was supplied by a vendor identified as “narinder-singh,” and versions 2.0 through 2.6.5 were identified as containing the vulnerability.

Cybersecurity Risks Plaguing Crypto


Security vulnerabilities are becoming increasingly common in the crypto industry. Two weeks ago, Bitcoin ATM manufacturer Lamassu Industries addressed a vulnerability that, if exploited, could have provided hackers with “full control” over its Bitcoin ATMs.

Gabriel Gonzalez, Director of Hardware Security at IOActive, reported that the exploited vulnerabilities could have allowed the hackers to empty all funds from the ATM and manipulate the note reader to display inaccurate deposit amounts.

The vulnerability was discovered when a team of ethical hackers from the security firm IOActive attempted to compromise Lamassu’s Bitcoin ATMs in 2023. The researchers identified and exploited multiple vulnerabilities, ultimately gaining full control over the ATMs.

The post Crypto Widget WordPress Plugin Flagged as “Critical” Cybersecurity Risk appeared first on Cryptonews.

0 comment
0
FacebookTwitterPinterestEmail

previous post
Do Kwon Wins Appeal as Montenegro Court Overturns Extradition
next post
ARK Invest and 21Shares Outline Cash Processes in New Ethereum ETF Bid

You may also like

Josh Fraser, Co-Founder of Origin Protocol, on Liquid...

Hong Kong Legislator Raises Concern Over Crypto Licensing...

Bitcoin Price Prediction: $150K Forecast and ETF Market...

Veteran Analyst Peter Brandt Predicts Bitcoin Price to...

Robinhood Implements Buying Restrictions on GameStop As Roaring...

Over $3 Billion Worth of ETH Withdrawn from...

Matter Labs Withdraws ‘ZK’ Trademark Application After Industry...

Rwanda to Roll Out CBDC By 2026 After...

El Salvador’s President Nayib Bukele Sworn in for...

FTX Estate Sells Off Remaining Anthropic Holdings Amid...

Enter Your Information Below To Receive Free Trading Ideas, Latest News And Articles.






    Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

    Recent Posts

    • EPA urged by state AGs to axe funds for ‘radical’ climate project accused of training judges
    • ‘Doctor Strangelove with a mustache’: Bolton blasted for ‘profiteering’ off US secrets by White House advisor
    • EPA urged to axe funds for ‘radical’ climate project accused of training judges, state AGs rally
    • Bolton may be in hot water as FBI investigation expands beyond controversial book
    • ‘Dr. Strangelove with a mustache’: Bolton blasted for ‘profiteering’ off US secrets by White House advisor

    Categories

    • Economy (7,136)
    • Editor's Pick (3,862)
    • Investing (2,826)
    • Stock (1,434)
    Email Whitelisting About Us Terms & Conditions Privacy Policy Contact Us

    Disclaimer: Evilsharktrades.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Copyright © 2024 EvilSharkTrades.com


    Back To Top
    Evil Shark Trades
    • Economy
    • Investing
    • Editor’s Pick
    • Stock