{"id":4578,"date":"2023-04-01T21:46:25","date_gmt":"2023-04-01T20:46:25","guid":{"rendered":"https:\/\/sajberinfo.com\/?p=4578"},"modified":"2023-04-11T21:46:21","modified_gmt":"2023-04-11T20:46:21","slug":"wordpress-elementor-pro-ranjivost","status":"publish","type":"post","link":"http:\/\/sajberinfo.com\/en\/2023\/04\/01\/wordpress-elementor-pro-ranjivost\/","title":{"rendered":"WordPress Elementor Pro ranjivost"},"content":{"rendered":"<p><span style=\"font-size: 14pt;\"><em>WordPress Elementor Pro<\/em> ranjivost se aktivno iskori\u0161tava i po dostupnim podacima milioni Internet stranica su u opasnosti.\u00a0<\/span><\/p>\n<div id=\"attachment_4584\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4584\" class=\"size-full wp-image-4584\" src=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/04\/Elementor-Pro-Vulnerability.jpg\" alt=\"Elementor Pro Vulnerability\" width=\"1024\" height=\"638\" srcset=\"https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/04\/Elementor-Pro-Vulnerability.jpg 1024w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/04\/Elementor-Pro-Vulnerability-300x187.jpg 300w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/04\/Elementor-Pro-Vulnerability-768x479.jpg 768w, https:\/\/sajberinfo.com\/wp-content\/uploads\/2023\/04\/Elementor-Pro-Vulnerability-18x12.jpg 18w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-4584\" class=\"wp-caption-text\"><em>WordPress Elementor Pro ranjivost; Dizajn: Sa\u0161a \u0110uri\u0107<\/em><\/p><\/div>\n<h2><em><strong><span style=\"font-size: 14pt;\">WordPress Elementor\u00a0<\/span><\/strong><\/em><\/h2>\n<p><span style=\"font-size: 14pt;\"><em>Elementor<\/em> je <em>WordPress<\/em> dodatak za pravljenje Internet stranica koji omogu\u0107ava korisnicima izradu profesionalnih Internet stranica bez poznavanja k\u00f4diranja. Procjenjuje se da pla\u0107enu <em>Pro<\/em> verziju koristi oko 12 miliona Internet stranica, zbog \u010dega ova ranjivost predstavlja veliku opasnost za korisnike.\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/p>\n<h3><strong><span style=\"font-size: 14pt;\">Ranjivost\u00a0<\/span><\/strong><\/h3>\n<p><span style=\"font-size: 14pt;\">Ranjivost <a href=\"https:\/\/blog.nintechnet.com\/high-severity-vulnerability-fixed-in-wordpress-elementor-pro-plugin\/\" target=\"_blank\" rel=\"noopener\">je otkrio <em>Jerome Bruandet<\/em> sigurnosni istra\u017eiva\u010d kompanije <em>NinTechNet<\/em><\/a> koji je primijetio da se iskori\u0161tava zajedno sa dodatkom <em>WooCommerce.<\/em> Ranjivost poga\u0111a verziju <em>3.11.6<\/em> i sve starije verzije <em>Elementor Pro<\/em> dodatka, dozvoljavaju\u0107i napada\u010du da izvr\u0161i promjene u pode\u0161avanju Internet stranice ili da izvr\u0161i kompletno preuzimanje.\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/p>\n<blockquote><p><em><span style=\"font-size: 14pt;\">\u201cAutentifikovani napada\u010d mo\u017ee iskoristiti ranjivost za kreiranje administratorskog naloga tako \u0161to \u0107e omogu\u0107iti registraciju i podesiti podrazumijevanu ulogu na \u201eadministrator\u201c, promijeniti adresu elektronske po\u0161te administratora ili preusmjeriti sav saobra\u0107aj na spoljnu zlonamjernu Internet lokaciju tako \u0161to \u0107e promijeniti URL adresu izme\u0111u mnogih drugih mogu\u0107nosti\u201c\u00a0<\/span><\/em><\/p>\n<p style=\"text-align: right;\"><em><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><span style=\"font-size: 14pt;\">&#8211; <a href=\"https:\/\/blog.nintechnet.com\/high-severity-vulnerability-fixed-in-wordpress-elementor-pro-plugin\/\" target=\"_blank\" rel=\"noopener\">Jerome Bruandet<\/a> &#8211;\u00a0<\/span><\/em><\/p>\n<\/blockquote>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\">Va\u017eno je napomenuti da da bi se ova ranjivost iskoristila, <em>WooCommerce<\/em> dodatak tako\u0111e mora biti instaliran na Internet lokaciji, koji aktivira odgovaraju\u0107i ranjivi modul na dodatku <em>Elementor Pro<\/em>.\u00a0<\/span><\/p>\n<h4><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/h4>\n<h4><strong><span style=\"font-size: 14pt;\">Aktivno iskori\u0161tavanje ranjivosti\u00a0<\/span><\/strong><\/h4>\n<p><span style=\"font-size: 14pt;\">Sigurnosna kompanija <em>PatchStack<\/em> u svom <a href=\"https:\/\/patchstack.com\/articles\/critical-elementor-pro-vulnerability-exploited\/\" target=\"_blank\" rel=\"noopener\">izvje\u0161taju<\/a> poja\u0161njava da napada\u010di aktivno iskori\u0161tavaju ovu ranjivost za preusmjeravanje posjetilaca pogo\u0111ene Internet stranice na zlonamjerne domene &#8220;<em>away[.]trackersline[.]com<\/em>&#8221; ili dobijanje tajnog pristupa preko opremljenih datoteka <em>wp-resortpark.zip, wp-rate.php<\/em> ili <i>l<\/i><em>ll.zip<\/em><i>.<\/i>\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><span style=\"font-size: 14pt;\"><a href=\"https:\/\/sajberinfo.com\/2023\/04\/11\/backdoor\/\" target=\"_blank\" rel=\"nofollow noopener\">Tajni pristup (eng. <\/a><em>backdoor),<\/em> napada\u010du omogu\u0107ava potpuno preuzimanje <em>WordPress<\/em> lokacije uz mogu\u0107nost kra\u0111e podataka ili instalacije dodatnog zlonamjernog k\u00f4da.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/p>\n<h5><strong><span style=\"font-size: 14pt;\">Za\u0161tita\u00a0<\/span><\/strong><\/h5>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><span style=\"font-size: 14pt;\">Korisnici koji koriste <em>Elementor Pro<\/em> dodatak bi trebalo da ga a\u017euriraju minimalno na verziju\u00a0 <em>3.11.7<\/em> ili <em>3.12.0<\/em> koja je trenutno zadnja dostupna verzija ovog dodatka.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><span style=\"font-size: 14pt;\">Sigurnosni istra\u017eiva\u010di su identifikovati nekoliko <em>IP<\/em> adresa sa kojih dolazi napad, pa korisnici mogu navedene adrese blokirati:\u00a0<\/span><\/p>\n<p><span style=\"font-size: 14pt;\" data-ccp-props=\"{&quot;134245417&quot;:true,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span style=\"font-size: 14pt;\">193.169.194.63\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span style=\"font-size: 14pt;\">193.169.195.64\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span style=\"font-size: 14pt;\">194.135.30.6\u00a0<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 14pt;\">Pro\u0161le sedmice <a href=\"https:\/\/sajberinfo.com\/2023\/03\/25\/wordpress-prinudno-azurira-woocommerce-dodatak\/\" target=\"_blank\" rel=\"nofollow noopener\"><em>WordPress<\/em> je prinudno a\u017eurirao <em>WooCommerce<\/em> dodatak<\/a> za Internet prodavnice, kako bi ispravio sigurnosnu ranjivost koja je omogu\u0107avala napada\u010du da dobije administratorske privilegije na ranjivoj Internet stranici.\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress Elementor Pro ranjivost se aktivno iskori\u0161tava i po dostupnim podacima milioni Internet stranica su u opasnosti.\u00a0 WordPress Elementor\u00a0 Elementor je WordPress dodatak za pravljenje Internet stranica koji omogu\u0107ava korisnicima izradu profesionalnih Internet stranica&#46;&#46;&#46;<\/p>","protected":false},"author":1,"featured_media":4584,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[142,325,309,259],"class_list":["post-4578","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hronike","tag-backdoor","tag-elementor","tag-woocommerce","tag-wordpress"],"_links":{"self":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/comments?post=4578"}],"version-history":[{"count":0,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/posts\/4578\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media\/4584"}],"wp:attachment":[{"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/media?parent=4578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/categories?post=4578"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/sajberinfo.com\/en\/wp-json\/wp\/v2\/tags?post=4578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}