Categories: More

VPS Hosting Company, Future Hosting, Warns of Hack Risk Inherent in Leaving Fresh WordPress Install in Its Default State

Future Hosting, a VPS hosting and dedicated server hosting provider, has warned WordPress hosting users of a new wave of attacks targeting fresh WordPress installations.

Fresh WordPress installations display an interface that is used to submit essential configuration data, including login and database credentials. This interface is not protected in any way, warns Future Hosting, and can be used by attackers to compromise the WordPress installation and potentially the server on which the WordPress site is hosted.

WordPress is typically installed by uploading its files to a hosting account or server. At this point, the installation is vulnerable. If an attacker is aware of the uncompleted configuration, they would be free to complete the process, creating a user with administration privileges and causing the site to use a database under the attacker’s control.

“We host thousands of WordPress sites on our VPS and dedicated server hosting platform,” said Maulesh Patel, VP of Operations of Future Hosting, “We hope to raise awareness of the risk inherent in leaving a fresh WordPress install in its default state. WordPress installations uploaded manually or via a script should be completed immediately.”

Once the attacker has control of the site, they can install custom plugins and execute arbitrary PHP code. WordFence reports that attackers are actively scanning the web for incomplete WordPress installations and using them to compromise hosting accounts.

There is no safe period during which an incomplete configuration can be exposed to the web. With a combination of automated scanning and scripts, bad actors could compromise an unconfigured WordPress site within seconds of it being uploaded to a server.

When installing WordPress on a hosting account or server, the configuration process should be completed immediately. Once the configuration and installation is complete, the site would no longer be vulnerable to these hacks.

Read more at VPS Hosting Company, Future Hosting, Warns of Hack Risk Inherent in Leaving Fresh WordPress Install in Its Default State on Website Hosting Review.

The post VPS Hosting Company, Future Hosting, Warns of Hack Risk Inherent in Leaving Fresh WordPress Install in Its Default State appeared first on Website Hosting Review.

Website Host Review

Recent Posts

Duos Technologies Group, Inc. Names Dipan Patel Chief Operating Officer

TL;DR Leadership appointment: Dipan Patel joins Duos as Chief Operating Officer, reporting to CEO Doug…

2 days ago

Microsoft Patches Entra ID RCE Vulnerability Exploited in Attacks

A maximum-severity vulnerability in Microsoft Entra ID allowed unauthenticated attackers to remotely execute code and…

2 days ago

Data centers face new scrutiny over heat island effect

Opposition to data center developments has been spreading due to local issues such as rising…

4 days ago

From Cost Drift to Sovereignty Demands: Why the Future of Cloud Is Selective

TL;DR While cloud computing has traditionally been defined by speed, scale, and flexibility, mature environments…

4 days ago

Capital, Power, and AI Reshape Latin America’s Digital Infrastructure Market

TL;DR AI and cloud demand are expanding Latin America’s digital infrastructure opportunity while increasing requirements…

2 weeks ago

Lightpath Expands into Atlanta with High-Capacity Managed Bandwidth Services

TL;DR Lightpath has entered the Greater Atlanta market with high-capacity Managed Bandwidth services. Wavelength and…

2 weeks ago