Security researchers from Wordfence and WebARX have identified several dangerous vulnerabilities in five plugins for the WordPress content management system, totaling over a million installations.
- in the plugin , which has over 700 thousand installations. The vulnerability has been assigned a risk level of 9 out of 10 (CVSS). It allows an authenticated user with subscriber rights to delete or hide (change the status to unpublished draft) any page on the site, as well as to substitute their own content on the pages.
The vulnerability in version 1.8.3. - in the plugin , which has over 200 thousand installations (real attacks on sites have been recorded, and since the emergence of information about the vulnerability, the number of installations has already decreased to 100 thousand). The vulnerability allows an unauthenticated visitor to clear the site's database content and reset the database to a fresh installation state. If there is a user named admin in the database, the vulnerability also allows full control over the site. The issue is caused by a failure when trying to authenticate a user attempting to send privileged commands via the script /wp-admin/admin-ajax.php. The problem has been fixed in version 1.6.2.
- in the plugin , used on 44 thousand sites. The vulnerability has been assigned a risk level of 9.8 out of 10. It allows an unauthenticated user to execute their PHP code on the server and substitute the site's administrator account by sending a special request via the REST API.
Exploitation of the vulnerability has already been recorded in the wild, but an update with the fix is not yet available. Users are advised to delete this plugin as soon as possible. - in the plugin , which has 60 thousand installations. The vulnerability has been assigned a risk level of 8.8 out of 10. It allows any authenticated visitor, including those with subscriber rights, to elevate their privileges to that of the site administrator or gain access to the wpCentral admin panel. The issue has been fixed in version 1.5.1.
- in the plugin , with around 65,000 installations. The issue has been assigned a severity level of 10 out of 10. This vulnerability allows an unauthenticated user to create an account with administrator rights (the plugin allows for the creation of registration forms, and the user can simply pass an additional field with a user role, assigning them administrator level). The issue has been fixed in version 3.1.1.
Additionally, it is worth noting networks distributing Trojan plugins and themes for WordPress. Malicious actors posted pirated copies of paid plugins on fake directory sites, integrating a backdoor for remote access and command loading from a control server. Once activated, the malicious code was used to inject harmful or deceptive advertisements (for example, warnings about the need to install antivirus software or update the browser), as well as for search engine optimization to promote sites distributing malicious plugins. Preliminary data suggests that over 20,000 sites were compromised using these plugins. Victims included a decentralized mining platform, a trading firm, a bank, several large companies, a payments solution provider using credit cards, IT companies, and others.
Source: opennet.ru
