# 数千个 WordPress 网站因 tagDiv 插件漏洞遭到黑客攻击

Source: https://www.zaihua.news/article/20765/

[返回新闻流](https://www.zaihua.news/)
2023年10月10日 · 08:03 · [在花新闻](https://www.zaihua.news/about/)

# 数千个 WordPress 网站因 tagDiv 插件漏洞遭到黑客攻击

千个运行 WordPress 内容管理系统的网站已被一个多产的黑客攻击，黑客利用了一个广泛使用的插件中最近修补的漏洞。

该易受攻击的插件称为 tagDiv Composer，是使用两个 WordPress 主题（[Newspaper](https://go.skimresources.com/?id=100098X1555750&isjs=1&jv=15.4.2-stackpath&sref=https%3A%2F%2Farstechnica.com%2Fsecurity%2F2023%2F10%2Fthousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability%2F&url=https%3A%2F%2Fthemeforest.net%2Fitem%2Fnewspaper%2F5489609&xs=1&xtz=-480&xuuid=4f56d7e9a847d25e048620351ea8e3cf&xcust=xid%3Afr1696887555596gah&xjsf=other_click__contextmenu%20%5B-1%5D)和[Newsmag](https://go.skimresources.com/?id=100098X1555750&isjs=1&jv=15.4.2-stackpath&sref=https%3A%2F%2Farstechnica.com%2Fsecurity%2F2023%2F10%2Fthousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability%2F&url=https%3A%2F%2Fthemeforest.net%2Fitem%2Fnewsmag-news-magazine-newspaper%2F9512331&xs=1&xtz=-480&xuuid=4f56d7e9a847d25e048620351ea8e3cf&xcust=xid%3Afr1696887555596jaa&xjsf=other_click__contextmenu%20%5B-1%5D)）的强制要求。这些主题可通过 Theme Forest 和 Envato 市场获得，下载量超过 155,000 次。

该漏洞编号为 CVE-2023-3169，是所谓的跨站点脚本 (XSS) 缺陷，允许黑客将恶意代码注入网页。该漏洞由越南研究员[Truoc Phan](https://www.wordfence.com/threat-intel/vulnerabilities/researchers/truoc-phan)发现，严重程度为 7.1 级（满分 10 级）。该漏洞在 tagDiv Composer 4.1 版中部分修复，并在 4.2 版中完全修补。

Source: [Ars Technica](https://arstechnica.com/security/2023/10/thousands-of-wordpress-sites-have-been-hacked-through-tagdiv-plugin-vulnerability/)

Via [Hua Hua](https://t.me/Hua%20Hua)

投稿：[@ZaiHuaBot](https://t.me/ZaiHuaBot)
频道：[@TestFlightCN](https://t.me/TestFlightCN)

[上一条24小时投稿精选 每日精选](https://www.zaihua.news/article/20764/)[下一条米哈游两次试图规避应用商店费用](https://www.zaihua.news/article/20766/)
