Skip to main content

Researchers find backdoor lurking in WordPress plugin used by schools


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

If you've used School Management Pro, it's time to check your site, stat.

 

DAN GOODIN - 5/20/2022

 

Researchers said on Friday that they found a malicious backdoor in a WordPress plugin that gave attackers full control of websites that used the package, which is marketed to schools.

The premium version of School Management, a plugin schools use to operate and manage their websites, has contained the backdoor since at least version 8.9, researchers at website security service Jetpack said in a blog post without ruling out that it had been present in earlier versions. This page from a third-party site shows that version 8.9 was released last August.

 

>> Full Article <<

2 replies

kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • May 23, 2022

Seems like the plugin company should at the very least pay for a vulnerability scan for their paying customers. The backdoor has been there since at least last August.


stlshark
New Member
Forum|alt.badge.img+1
  • New Member
  • 93 replies
  • May 23, 2022

As if security wasn’t hard enough for schools. Things like this really do not help an already overwhelmed and underfunded administrator. 


Reply