For a detailed advisory, download the pdf file here.
Hackers are actively exploiting a zero-day vulnerability on the famous Fancy Product Designer, a WordPress plugin, since May 16, 2021. This plugin has been installed on over 17,000 sites. Hive Pro Threat Research Team advises all the users to uninstall this plugin until an official patch is released.
Vulnerability Details
CVE IDAffected VersionsVulnerability NameCVE-2021-243704.6.8Unauthenticated Arbitrary File Upload and Remote Code Execution in WordPress plugin Fancy Product Designer
Indicators of Compromise
https://thehackernews.com/2021/06/hackers-actively-exploiting-0-day-in.html
https://www.wordfence.com/blog/2021/06/critical-0-day-in-fancy-product-designer-under-active-attack/
