Automatically translated.View original post

An SQL Injection bug was found on the Ally plug-in hitting the website.

An SQL Injection bug was found on the Ally plug-in, hitting over 4 lakh Wordpress websites.

Shooting SQL or SQL Injection code is known as a classic website hacking method that, even after decades, still has a vulnerability for hackers to use.

According to a report by the website Security Affair, a security vulnerability has been detected on a Wordpress plug-in called Ally (also known as One Click Accessibility). This add-in was originally intended to create a website for people with disabilities to use. This plug-in has a lot of features, including a Scanner, a Scanner for people with disabilities to use with AI recommendations, a lot of useful widgets, etc. This plug-in is very popular with up to 4 active websites. Hundred thousand websites.

But in February, a researcher from Acquia, a cloud services company, detected a CVE-2026-2413 vulnerability (with a CVSS score of 7.5). This vulnerability is an insecure handling vulnerability in the Subscribers Query section. The plug-in creates an SQL JOIN query with the URL Parameter of the page but does not use Wordpress's wpdb- > prepare () function. This function acts to avoid special characters and a meter. With Query, even if using the esc _ url _ raw () function, it will not be able to prevent SQL Injection, leading to the use of SQL Injection to steal data from the database on the website.

But the good news is that this vulnerability was quickly patched after Wordfence, a security plugin developer on the Wordpress website, organized the Wordfence Bug Bounty Program for bug hunting and received such bug reports from the researchers, as well as a reward for this bug of US $800 (26,143.60 baht), immediately reported it to Elementor, the developer of the plugin, on February 13. The development team responded on the 15th and released the patch on the 23rd in the same month.

This vulnerability will affect all versions of the Ally plug-in up to 4.0.3. Users can plug this vulnerability only by upgrading it to version 4.1.0. Therefore, ask the administrator of the website that uses the plug-in to update it to the latest version immediately.

# Trending # lemon 8 diary # Drug sign with lemon8 # sqlinjection # freedomhack

4/2 Edited to

... Read moreในยุคที่เว็บไซต์กลายเป็นส่วนสำคัญสำหรับธุรกิจและการสื่อสาร ช่องโหว่ด้านความปลอดภัยโดยเฉพาะอย่างยิ่ง SQL Injection ยังคงเป็นภัยคุกคามที่ไม่ควรมองข้าม แม้เทคโนโลยีและแพลตฟอร์มต่าง ๆ จะมีการพัฒนาและอัปเดตแก้ไขอย่างต่อเนื่องก็ตาม จากประสบการณ์การดูแลเว็บไซต์และติดตามปัญหาความปลอดภัยหลายครั้ง พบว่าปลั๊กอินที่ช่วยเพิ่มฟีเจอร์ให้กับเว็บไซต์ เช่น Ally ที่เน้นเรื่อง Accessibility ซึ่งเป็นส่วนสำคัญของเว็บยุคใหม่ กลับกลายเป็นช่องทางให้แฮกเกอร์ผ่านเข้าถึงฐานข้อมูลได้โดยง่ายถ้าหากไม่ได้รับการอัปเดตอย่างทันท่วงที สิ่งที่ผู้ดูแลเว็บควรตระหนักคือการเลือกและใช้งานปลั๊กอินต้องดูแลในด้านความปลอดภัยอย่างเคร่งครัด ไม่ใช่แค่ฟีเจอร์ที่ปลั๊กอินนั้นนำเสนอ อีกทั้งเมื่อได้รับแจ้งช่องโหว่หรือมีข่าวการแพตช์ ควรเร่งรีบทำการอัปเดตเวอร์ชันใหม่ทันทีเพื่อลดความเสี่ยงต่อการถูกโจมตี ที่สำคัญปลั๊กอิน Ally มีฟังก์ชันที่ช่วยให้เว็บไซต์ใช้งานง่ายขึ้นสำหรับผู้พิการ เช่น AI Suggestion และ widget ที่ทำให้เว็บมีความน่าเข้าถึงยิ่งขึ้น แต่การปล่อยให้ช่องโหว่เช่น SQL Injection อยู่โดยไม่ได้รับการแก้ไข อาจนำไปสู่การขโมยข้อมูลสำคัญของเว็บไซต์และผู้ใช้งานได้ จากเหตุการณ์นี้ ผู้ดูแลเว็บ Wordpress ควรเพิ่มมาตรการตรวจสอบและตั้งค่าความปลอดภัยเสริม เช่น ใช้ปลั๊กอินรักษาความปลอดภัย ตรวจสอบ log การเข้าใช้งานอย่างสม่ำเสมอ และให้ความรู้กับทีมงานเกี่ยวกับช่องโหว่และวิธีป้องกัน เพื่อรักษาความน่าเชื่อถือและปลอดภัยในโลกออนไลน์อย่างยั่งยืน