{"id":69581,"date":"2020-02-20T20:42:04","date_gmt":"2020-02-20T17:42:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok"},"modified":"2020-03-03T16:11:07","modified_gmt":"2020-03-03T13:11:07","slug":"uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","title":{"rendered":"Vulnerabilities in WordPress plugins with over a million installs.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Security researchers from Wordfence and WebARX have identified several dangerous vulnerabilities in five plugins for the WordPress content management system, totaling over a million installations.<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/improper-access-controls-in-gdpr-cookie-consent-plugin\/\">The vulnerability<\/a><\/noindex> in the plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/cookie-law-info\/\">GDPR Cookie Consent<\/a><\/noindex>, which has over 700 thousand installations. The vulnerability has been assigned a risk level of 9 out of 10 (CVSS). It allows an authenticated user with subscriber rights to delete or hide (change the status to unpublished draft) any page on the site, as well as to substitute their own content on the pages.<br \/>\nThe vulnerability <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset\/2241572\/\">has been closed<\/a><\/noindex> in version 1.8.3.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/critical-issue-in-themegrill-demo-importer\/\">The vulnerability<\/a><\/noindex> in the plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/themegrill-demo-importer\/\">ThemeGrill Demo Importer<\/a><\/noindex>, which has over 200 thousand installations (real attacks on sites have been recorded, and since the emergence of information about the vulnerability, the number of installations has already decreased to 100 thousand). The vulnerability allows an unauthenticated visitor to clear the site's database content and reset the database to a fresh installation state. If there is a user named admin in the database, the vulnerability also allows full control over the site. The issue is caused by a failure when trying to authenticate a user attempting to send privileged commands via the script \/wp-admin\/admin-ajax.php. The problem has been fixed in version 1.6.2.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/zero-day-vulnerability-in-themerex-addons-plugin-exploited-in-the-wild\/\">The vulnerability<\/a><\/noindex> in the plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/themerex.net\/wp\/download_plugins\/themerex-addons\/\">ThemeREX Addons<\/a><\/noindex>, used on 44 thousand sites. The vulnerability has been assigned a risk level of 9.8 out of 10. It allows an unauthenticated user to execute their PHP code on the server and substitute the site's administrator account by sending a special request via the REST API.<br \/>\n Exploitation of the vulnerability has already been recorded in the wild, but an update with the fix is not yet available. Users are advised to delete this plugin as soon as possible.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/vulnerability-in-wpcentral-plugin-leads-to-privilege-escalation\/\">The vulnerability<\/a><\/noindex> in the plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wp-central\/\">wpCentral<\/a><\/noindex>, which has 60 thousand installations. The vulnerability has been assigned a risk level of 8.8 out of 10. It allows any authenticated visitor, including those with subscriber rights, to elevate their privileges to that of the site administrator or gain access to the wpCentral admin panel. The issue has been fixed in version 1.5.1.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/02\/critical-vulnerability-in-profile-builder-plugin-allowed-site-takeover\/\">The vulnerability<\/a><\/noindex> in the plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/profile-builder\/\">Profile Builder<\/a><\/noindex>, with around 65,000 installations. The issue has been assigned a severity level of 10 out of 10. This vulnerability allows an unauthenticated user to create an account with administrator rights (the plugin allows for the creation of registration forms, and the user can simply pass an additional field with a user role, assigning them administrator level). The issue has been fixed in version 3.1.1.\n<\/ul>\n<p>Additionally, it is worth noting <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.prevailion.com\/2020\/02\/phps-labyrinth-weaponized-wordpress.html\">the discovery of<\/a><\/noindex> networks distributing Trojan plugins and themes for WordPress. Malicious actors posted pirated copies of paid plugins on fake directory sites, integrating a backdoor for remote access and command loading from a control server. Once activated, the malicious code was used to inject harmful or deceptive advertisements (for example, warnings about the need to install antivirus software or update the browser), as well as for search engine optimization to promote sites distributing malicious plugins. Preliminary data suggests that over 20,000 sites were compromised using these plugins. Victims included a decentralized mining platform, a trading firm, a bank, several large companies, a payments solution provider using credit cards, IT companies, and others.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52398\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 GDPR Cookie Consent, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u044c\u0448\u0435 700 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 9 \u0438\u0437 10 (CVSS). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 \u043f\u043e\u0434\u043f\u0438\u0441\u0447\u0438\u043a\u0430 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u0438\u043b\u0438 \u0441\u043a\u0440\u044b\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-69581","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-20T17:42:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:11:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilities in WordPress plugins with over a million installations | ProHoster","description":"Security researchers from Wordfence and WebARX have identified several dangerous vulnerabilities in five plugins for the WordPress content management system, totaling over a million installations.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Wordfence \u0438 WebARX \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043f\u044f\u0442\u0438 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u0432 \u0441\u0443\u043c\u043c\u0435 \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-milliona-ustanovok","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-20T17:42:04+00:00","article:modified_time":"2020-03-03T13:11:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"69581","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:20:24","updated":"2022-10-05 19:44:59","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/69581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=69581"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/69581\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=69581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=69581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=69581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}