{"id":55336,"date":"2020-01-18T00:00:00","date_gmt":"2020-01-17T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok"},"modified":"2020-02-18T14:03:26","modified_gmt":"2020-02-18T11:03:26","slug":"kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","title":{"rendered":"Vulnerabilit\u00e0 critiche nei plugin di WordPress con oltre 400.000 installazioni","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In tre plugin popolari per il sistema di gestione dei contenuti web WordPress, che superano le 400.000 installazioni, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin\/\">sono state individuate<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">vulnerabilit\u00e0 critiche<\/a><\/noindex>:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">Vulnerabilit\u00e0<\/a><\/noindex> nel plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/iwp-client\/\">InfiniteWP Client<\/a><\/noindex>, con oltre 300.000 installazioni attive, consente di connettersi senza autenticazione come amministratore del sito. Poich\u00e9 il plugin \u00e8 progettato per unificare la gestione di pi\u00f9 siti su un server, un attaccante pu\u00f2 ottenere il controllo su tutti i siti gestiti tramite InfiniteWP Client. Per attaccare \u00e8 sufficiente conoscere il login di un utente con diritti di amministratore, dopo di che, inviando una richiesta POST appositamente formattata (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/critical-authentication-bypass-vulnerability-in-infinitewp-client-plugin\/\">specificando<\/a><\/noindex> Il parametro \u00abadd_site\u00bb o \u00abreadd_site\u00bb consente di accedere all'interfaccia di gestione con i diritti di questo utente. La vulnerabilit\u00e0 \u00e8 causata da un errore nell'implementazione della funzione di accesso automatico.<br \/>\nProblema <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&#038;sfph_mail=&#038;reponame=&#038;new=2224159%40iwp-client%2Ftrunk&#038;old=2213507%40iwp-client%2Ftrunk&#038;sfp_email=&#038;sfph_mail=\">\u00e8 stato risolto<\/a><\/noindex> nella versione InfiniteWP Client 1.9.4.5.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.wordfence.com\/blog\/2020\/01\/easily-exploitable-vulnerabilities-patched-in-wp-database-reset-plugin\/\">Due vulnerabilit\u00e0<\/a><\/noindex> nel plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wordpress-database-reset\/\">WP Database Reset<\/a><\/noindex>, utilizzato su circa 80.000 siti. La prima vulnerabilit\u00e0 consente di ripristinare il contenuto di qualsiasi tabella nel database senza autenticazione (riportandolo allo stato di una nuova installazione di WordPress, rimuovendo i dati associati al sito). Il problema \u00e8 causato dalla mancanza di un controllo sui permessi durante l'esecuzione della funzione di reset.\n<p>La seconda vulnerabilit\u00e0 in WP Database Reset richiede l'accesso autenticato (\u00e8 sufficiente avere un account con le minime autorizzazioni di abbonato) e consente di ottenere privilegi di amministratore del sito (\u00e8 possibile ottenere l'eliminazione di tutti gli utenti dalla tabella wp_users, dopo di che l'utente rimanente sar\u00e0 trattato come amministratore). I problemi sono stati risolti nella versione 3.15.<\/p>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.webarxsecurity.com\/vulnerability-infinitewp-client-wp-time-capsule\/\">Vulnerabilit\u00e0<\/a><\/noindex> nel plugin <noindex><a rel=\"nofollow\" href=\"https:\/\/wordpress.org\/plugins\/wp-time-capsule\/\">WP Time Capsule<\/a><\/noindex>, con oltre 20.000 installazioni, consente di connettersi con diritti di amministratore senza autenticazione. Per effettuare l'attacco \u00e8 sufficiente aggiungere alla richiesta POST la stringa IWP_JSON_PREFIX, la cui presenza attiva la funzione wptc_login_as_admin senza alcun controllo. Il problema <noindex><a rel=\"nofollow\" href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&#038;sfph_mail=&#038;reponame=&#038;new=2224224%40wp-time-capsule%2Ftrunk&#038;old=2216966%40wp-time-capsule%2Ftrunk&#038;sfp_email=&#038;sfph_mail=\">\u00e8 stato risolto<\/a><\/noindex> nella versione 1.21.16.\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/i.imgur.com\/29uHqJv.png\"><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 critiche nei plugin di WordPress con oltre 400.000 installazioni\" src=\"\/wp-content\/uploads\/2020\/01\/53d43c890538b557c227c525ccbb15b2.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52207\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 \u043f\u043b\u0430\u0433\u0438\u043d\u0435 InfiniteWP Client, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 300 \u0442\u044b\u0441\u044f\u0447 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u0442\u044c\u0441\u044f \u0431\u0435\u0437 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430 \u0441\u0430\u0439\u0442\u0430. \u0422\u0430\u043a \u043a\u0430\u043a \u043f\u043b\u0430\u0433\u0438\u043d \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d \u0434\u043b\u044f \u0443\u043d\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u043c\u0438 \u0441\u0430\u0439\u0442\u0430\u043c\u0438 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435, \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0439 \u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c \u0441\u0440\u0430\u0437\u0443 \u0437\u0430 \u0432\u0441\u0435\u043c\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":55337,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-55336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-17T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 critiche nei plugin di WordPress, con oltre 400.000 installazioni | ProHoster","description":"In tre plugin popolari per il sistema di gestione dei contenuti web WordPress, che superano le 400.000 installazioni,","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445, \u0438\u043c\u0435\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a | ProHoster","og:description":"\u0412 \u0442\u0440\u0435\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043f\u043b\u0430\u0433\u0438\u043d\u0430\u0445 \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f web-\u043a\u043e\u043d\u0442\u0435\u043d\u0442\u043e\u043c WordPress, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0431\u043e\u043b\u0435\u0435 400 \u0442\u044b\u0441\u044f\u0447 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a,","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/kriticheskie-uyazvimosti-v-wordpress-plaginah-imeyushhih-bolee-400-tysyach-ustanovok","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-17T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55336","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:03:51","updated":"2022-10-09 06:33:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/55336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=55336"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/55336\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/55337"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=55336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=55336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=55336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}