{"id":17326891,"date":"2024-01-08T17:29:00","date_gmt":"2024-01-08T17:29:00","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=17326891"},"modified":"2024-01-08T19:11:04","modified_gmt":"2024-01-08T19:11:04","slug":"wordpress-scam","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/wordpress-scam\/","title":{"rendered":"WordPress scam"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Not sure where to report this but I received an email from my wordpress site advising me to download a plugin to fix a vulnerability. It really looks legit and it almost tricked me but I found it odd to have to download a plugin and also the website it links to is <strong>ca.en&lt;span style=&#8221;text-decoration: underline;&#8221;&gt;-&lt;\/span&gt;wordpress.org<\/strong> (notice the dash in the URL:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Dear user<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The WordPress Security Team has detected a critical vulnerability on the website: <strong>&lt;u&gt;store.beatate.ca&lt;\/u&gt;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Remote Code Execution (RCE) vulnerability found on your site is categorized as <strong>a critical threat<\/strong>, potentially allowing malicious code execution and putting your data, user details, and overall site security at risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>We urge you to apply the CVE-2024-46188 Patch immediately<\/strong>, as we are working on addressing this crucial security hole in the upcoming WordPress version.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Simply download the plugin by clicking the button below, install and activate it on your site.<\/strong> This ensures swift and hassle-free defense against potential exploits and malicious actions linked to this vulnerability.<\/p>\n<\/blockquote>\n","protected":false},"template":"","class_list":["post-17326891","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17326891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17326891\/revisions"}],"predecessor-version":[{"id":17327102,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/17326891\/revisions\/17327102"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=17326891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}