Office of Information Technology
December 1, 2023
Tags Phishing Email (on campus)

Fake Critical Vulnerability in WordPress

Phish Bowl Alerts

Be vigilant and on the lookout for fraudulent security notices imploring you to download and run a patch or plugin to address a critical vulnerability in your software. See here for a recent example of a scam message purported to be from WordPress, the popular website building service. The message pressures users to "immediately" download and run the "CVE-2023-45124 Patch" though no vulnerability utilizing that designation exists.

A screenshot of a fraudulent WordPress email attempting to pressure users into downloading a malicious file.