Critical vulnerability in the WordPress plugin File Manager, which has 700 thousand installations.

In the WordPress plugin File Manager, which has over 700 thousand active installations, identified a vulnerability allows arbitrary commands and PHP scripts to be executed on the server. The issue appears in File Manager releases from 6.0 to 6.8 and has been fixed in release 6.9.

The File Manager plugin provides tools for file management for WordPress administrators, using the built-in library for low-level file operations elFinder. The source code of the elFinder library contains files with code examples that are supplied in the working directory with the '.dist' extension. The vulnerability is caused by the fact that when shipping the library, the file 'connector.minimal.php.dist' was renamed to 'connector.minimal.php' and became executable upon receiving external requests. This script allows any file operations (upload, open, editor, rename, rm, etc.) to be performed, as its parameters are passed to the run() function of the main plugin, which can be used to replace PHP files in WordPress and execute arbitrary code.

The danger is exacerbated by the fact that the vulnerability is already a layer used for automated attacks, during which an image containing PHP code is uploaded to the directory 'plugins/wp-file-manager/lib/files/' using the 'upload' command, and is then renamed to a PHP script with a randomly chosen name containing 'hard' or 'x.', for example, hardfork.php, hardfind.php, x.php, etc. After the PHP code runs, it adds a backdoor to the files /wp-admin/admin-ajax.php and /wp-includes/user.php, providing attackers access to the site's admin interface. Exploitation occurs by sending a POST request to the file 'wp-file-manager/lib/php/connector.minimal.php'.

Notably, after a breach, changes are made not only to leave the backdoor but also to protect against further accesses to the file connector.minimal.php, which contains the vulnerability, in order to block the possibility of attacks on the server by other attackers.
The first attack attempts were detected on September 1 at 7 AM (UTC). In
12:33 (UTC) The developers of the File Manager plugin released a patch. According to the company Wordfence, which identified the vulnerability, their firewall blocked around 450,000 exploitation attempts in one day. Network scanning revealed that 52% of the websites using this plugin have not yet updated and remain vulnerable. After installing the update, it makes sense to check the http server log for requests to the script 'connector.minimal.php' to determine if the system has been compromised.

Additionally, a corrective release can be noted. WordPress 5.5.1 which includes 40 fixes..

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster