{"id":55336,"date":"2020-01-18T00:00:00","date_gmt":"2020-01-17T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok"},"modified":"2020-02-18T14:03:26","modified_gmt":"2020-02-18T11:03:26","slug":"kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","title":{"rendered":"Vulnerabilidades cr\u00edticas en los plugins de WordPress con m\u00e1s de 400 mil instalaciones","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En tres plugins populares para el sistema de gesti\u00f3n de contenido web WordPress, que suman m\u00e1s de 400 mil instalaciones, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin\/\">se han identificado<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">vulnerabilidades cr\u00edticas<\/a><\/noindex>:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">Vulnerabilidad<\/a><\/noindex> en el plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/iwp-client\/\">InfiniteWP Client<\/a><\/noindex>, que cuenta con m\u00e1s de 300 mil instalaciones activas, permite acceder sin autenticaci\u00f3n como administrador del sitio. Dado que el plugin est\u00e1 dise\u00f1ado para unificar la gesti\u00f3n de varios sitios en el servidor, un atacante puede tomar control de todos los sitios utilizados con InfiniteWP Client. Para llevar a cabo el ataque, solo es necesario conocer el nombre de usuario de un administrador, tras lo cual, enviando una solicitud POST especialmente dise\u00f1ada (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/critical-authentication-bypass-vulnerability-in-infinitewp-client-plugin\/\">indicando<\/a><\/noindex> el par\u00e1metro \u00abadd_site\u00bb o \u00abreadd_site\u00bb) se puede acceder a la interfaz de gesti\u00f3n con los derechos de este usuario. La vulnerabilidad es causada por un error en la implementaci\u00f3n de la funci\u00f3n de inicio de sesi\u00f3n autom\u00e1tico.<br \/>\nProblema <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&#038;sfph_mail=&#038;reponame=&#038;new=2224159%40iwp-client%2Ftrunk&#038;old=2213507%40iwp-client%2Ftrunk&#038;sfp_email=&#038;sfph_mail=\">se solucion\u00f3<\/a><\/noindex> en la versi\u00f3n InfiniteWP Client 1.9.4.5.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin\/\">Dos vulnerabilidades<\/a><\/noindex> en el plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wordpress-database-reset\/\">WP Database Reset<\/a><\/noindex>, utilizada en aproximadamente 80 mil sitios. La primera vulnerabilidad permite, sin autenticaci\u00f3n, restablecer a su estado inicial el contenido de cualquier tabla en la base de datos (haci\u00e9ndola volver al estado de una nueva instalaci\u00f3n de WordPress, eliminando los datos relacionados con el sitio). El problema es causado por la falta de verificaci\u00f3n de los permisos durante la ejecuci\u00f3n de la funci\u00f3n de restablecimiento.\n<p>La segunda vulnerabilidad en WP Database Reset requiere acceso autenticado (suficiente con tener una cuenta con permisos m\u00ednimos de suscriptor) y permite obtener privilegios de administrador del sitio (lo que puede llevar a eliminar a todos los usuarios de la tabla wp_users, tras lo cual el usuario restante ser\u00e1 tratado como administrador). Los problemas han sido corregidos en la versi\u00f3n 3.15.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">Vulnerabilidad<\/a><\/noindex> en el plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wp-time-capsule\/\">WP Time Capsule<\/a><\/noindex>, que cuenta con m\u00e1s de 20 mil instalaciones, permite acceder con derechos de administrador sin autenticaci\u00f3n. Para llevar a cabo el ataque, solamente es necesario a\u00f1adir en la solicitud POST la cadena IWP_JSON_PREFIX, que activa la funci\u00f3n wptc_login_as_admin sin ninguna verificaci\u00f3n. El problema <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&#038;sfph_mail=&#038;reponame=&#038;new=2224224%40wp-time-capsule%2Ftrunk&#038;old=2216966%40wp-time-capsule%2Ftrunk&#038;sfp_email=&#038;sfph_mail=\">se solucion\u00f3<\/a><\/noindex> ha sido corregido en la versi\u00f3n 1.21.16.\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/i.imgur.com\/29uHqJv.png\"><img decoding=\"async\" alt=\"Vulnerabilidades cr\u00edticas en los plugins de WordPress con m\u00e1s de 400 mil instalaciones\" src=\"\/wp-content\/uploads\/2020\/01\/53d43c890538b557c227c525ccbb15b2.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52207\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 InfiniteWP Client, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 300 \u0442\u044b\u0441\u044f\u0447 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430 \u0441\u0430\u0439\u0442\u0430. \u0422\u0430\u043a \u043a\u0430\u043a \u043f\u043b\u0430\u0433\u0438\u043d \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d \u0434\u043b\u044f \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u043c\u0438 \u0441\u0430\u0439\u0442\u0430\u043c\u0438 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435, \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c \u0441\u0440\u0430\u0437\u0443 \u0437\u0430 \u0432\u0441\u0435\u043c\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":55337,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-55336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-17T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vulnerabilidades cr\u00edticas en los plugins de WordPress con m\u00e1s de 400 mil instalaciones | ProHoster","description":"En tres plugins populares para el sistema de gesti\u00f3n de contenido web WordPress, que suman m\u00e1s de 400 mil instalaciones,","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster","og:description":"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-17T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55336","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:03:51","updated":"2022-10-09 06:33:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/55336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=55336"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/55336\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/55337"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=55336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=55336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=55336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}