The threat actors target four WordPress plugins and fifteen Epsilon Framework themes, one of which has no available patch.
Some of the targeted plugins were patched all the way back in 2018, while others had their vulnerabilities addressed as recently as this week.
You certainly always want to ensure you have a good security plugin installed which prevents brute force attacks, and that you only have the active themes and plugins installed, and that they are all set to auto update enabled.
See Massive attack against 1.6 million WordPress sites underway
#technology #security #wordpress
Wordfence analysts report having detected a massive wave of attacks in the last couple of days, originating from 16,000 IPs and targeting over 1.6 million WordPress sites.