Critical vulnerabilities in WordPress plugins with over 400,000 installations

In three popular plugins for the WordPress content management system, with over 400 thousand installations, three vulnerabilities have been identified critical vulnerabilities:

  • The vulnerability in the plugin InfiniteWP Client, which has more than 300 thousand active installations, allows connection without authentication as a site administrator. Since the plugin is designed to unify management of multiple sites on a server, an attacker can gain control over all sites serviced using InfiniteWP Client. To carry out the attack, it is sufficient to know the login of a user with administrator rights, after which a specially crafted POST request can be sent (by specifying the parameter 'add_site' or 'readd_site') to access the management interface with this user's rights. The vulnerability is caused by an error in the implementation of the auto-login function.
    The Problem has been closed in version InfiniteWP Client 1.9.4.5.
  • Two vulnerabilities in the plugin WP Database Reset, which is used on approximately 80 thousand sites. The first vulnerability allows the contents of any DB tables to be reset to their initial state without authentication (bringing them to a fresh WordPress installation state, removing site-related data). This issue is caused by a lack of authorization checks during the reset function execution.

    The second vulnerability in WP Database Reset requires authenticated access (it is sufficient to have an account with minimal subscriber rights) and allows gaining site administrator privileges (leading to the deletion of all users from the wp_users table, after which the remaining user will be treated as an administrator). The issues have been resolved in version 3.15.

  • The vulnerability in the plugin WP Time Capsule, which has over 20 thousand installations, allows connection with administrator rights without authentication. To carry out the attack, it is enough to add the line IWP_JSON_PREFIX to the POST request, which, when present, triggers the function wptc_login_as_admin without any checks. The issue has been closed has been fixed in version 1.21.16.

    Critical vulnerabilities in WordPress plugins with over 400,000 installations

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster