Online Services

Blog

  • SQL Injection Vulnerability in NextGEN Gallery for WordPress

    SQL Injection Vulnerability in NextGEN Gallery for WordPress

    SQL Injection Vulnerability in NextGEN Gallery for WordPress

    As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While working on the WordPress plugin NextGEN Gallery, we discovered a severe SQL Injection vulnerability. This vulnerability allows an unauthenticated user to grab data from the victim’s website database, including sensitive user information.

    Are You at Risk?

    This vulnerability can be exploited by attackers in at least two different scenarios:

    1. If you use a NextGEN Basic TagCloud Gallery on your site, or
    2. If you allow your users to submit posts to be reviewed (contributors).

    Continue reading SQL Injection Vulnerability in NextGEN Gallery for WordPress at Sucuri Blog.

  • Stored XSS in WordPress Core

    Stored XSS in WordPress Core

    Stored XSS in WordPress Core

    As you might remember, we recently blogged about a critical Content Injection Vulnerability in WordPress which allowed attackers to deface vulnerable websites. While our original disclosure only described one vulnerability, we actually reported two to the WordPress team. As it turns out, it was possible to leverage the content injection issue to achieve a stored cross-site scripting attack. This issue was patched in WordPress 4.7.3.

    Are You at Risk?

    This vulnerability has been present in WordPress for quite a while, well before 4.7.

    Continue reading Stored XSS in WordPress Core at Sucuri Blog.

  • SEO Spam Campaign Exploiting WordPress REST API Vulnerability

    SEO Spam Campaign Exploiting WordPress REST API Vulnerability

    SEO Spam Campaign Exploiting WordPress REST API Vulnerability

    Just over a week ago, WordPress released version 4.7.3 to patch multiple security issues. Despite the automatic update feature provided by many hosting companies, there are still many WordPress websites that have not been updated. In fact, we are seeing quite a few sites that are still using versions 4.7 and 4.7.1, which are vulnerable to the WordPress REST API vulnerability patched in early February  (version 4.7.2). This more serious vulnerability allows attackers to create, delete, and modify posts on vulnerable websites without authorization.

    Continue reading SEO Spam Campaign Exploiting WordPress REST API Vulnerability at Sucuri Blog.

  • Malicious Subdirectories Strike Again

    Malicious Subdirectories Strike Again

    Malicious Subdirectories Strike Again

    In a previous post, we illustrated how attackers were fetching information from compromised sites under their control to display spam content on other hacked websites. By adding malicious files into a directory and using the victim’s database structure, attackers were able to inject ads and promote their products.

    This time, attackers used a similar technique with a little bit more sophistication to achieve their goals.

    Essay Spam Campaign

    This technique is now being used to distribute essay spam targeted at students.

    Continue reading Malicious Subdirectories Strike Again at Sucuri Blog.