Online Services

Blog

  • Serious Vulnerability in All in One SEO Pack Plugin 2.3.6.1 and earlier

    There is a serious stored cross site scripting (XSS) vulnerability in All in One SEO Pack Plugin versions 2.3.6.1 and older. This plugin is installed on over 1 million active websites and is extremely popular and widely used.

    The vulnerability allows an attacker to send a malicious HTTP User-Agent or Referrer header to the site containing an XSS payload. If the administrator then visits their admin panel and views the “Bad Bot Blocker” settings page in this plugin, the attacker can take full control of their site.

    This vulnerability is only exploitable on sites that have the “Track Blocked Bots” setting enabled. This setting is not enabled by default. We do not have definitive data to indicate how many users of the plugin have enabled this feature. However, this plugin is extremely popular:

    • All in One SEO Pack has been downloaded over 28 million times (this includes upgrades)
    • It has been around for over 9 years
    • It is one of the most downloaded WordPress plugins. Contrary to its claim of being the most downloaded WordPress plugin, Akismet, Yoast SEO and Contact Form 7 have more downloads.

    This attack has a CVSS score of 8.8 (High), however due to the extremely wide-spread use of the All in One SEO Pack plugin, we are adding this additional advisory: Wordfence rates this vulnerability as very serious because it is useful to an attacker and widely exploitable. 

    If as few as 10% of sites have the feature enabled, assuming an install base of 5 million active sites, that creates 500,000 vulnerable sites.

    What to do

    Wordfence Premium customers are already protected against exploitation of this vulnerability. We released a firewall rule to our premium customers early this morning which blocks this exploit. Our free customers will receive the rule on August 12th.

    If you are using the free version of Wordfence or are not using Wordfence at all, you will need to immediately upgrade to All in One SEO Pack Plugin version 2.3.7 which contains the fix for this security issue.

    Additional Details

    This vulnerability was discovered by David Vaartjes and you can find the full technical details of the vulnerability on his site. Congratulations David, from the Wordfence team, on unearthing this serious issue.

    A proof of concept has been published on exploit-db, which means this attack is already in the wild.

    All in One SEO Pack is made by Semper Fi Web Design.

    This story has received coverage in the past few hours from The RegisterWP Tavern, Softpedia.com and is on the IDG News Service which includes CIO.com and PCWorld.

    Timeline

    We encourage you to share this post with the larger WordPress community to create awareness of this security issue.

    The post Serious Vulnerability in All in One SEO Pack Plugin 2.3.6.1 and earlier appeared first on Wordfence.

  • 2 Vulnerabilities in Squirrly SEO plugin 6.1.4 and older

    Today the Squirrly SEO team released version 6.1.5 of their WordPress plugin, fixing two security vulnerabilities. They have over 20,000 active users according to wordpress.org. Panagiotis Vagenas, Security Analyst here at Wordfence discovered the vulnerabilities. Details were shared with the author and firewall rules were added to the Wordfence Threat Defense Feed on Friday. The path traversal and privilege escalation vulnerabilities impact versions 6.1.4 and older.

    Vulnerability 1: Privilege Escalation

    CVSS Severity: 8.8 (High)

    This vulnerability allows an attacker to modify plugin settings on a site with registration enabled. On a stand-alone basis the value to an attacker is relatively low, enabling them to do things like add or change the site favicon, upload featured images for posts or retrieve SEO settings for a post. As you’ll see below, the real danger with this vulnerability is when it is used in conjunction with another.

    Vulnerability 2: Path Traversal

    CVSS Severity: 8.1 (High)

    This vulnerability allows an attacker to download any file from a WordPress server, including the wp-config.php file. That file includes database credentials for the website and other information that could potentially enable an attacker to gain full control of the site. In order to exploit this vulnerability there are two conditions that must be met: a specific plugin parameter must be set to a specific value and a favicon must be present. We have no way of estimating the percentage of websites running the Squirrly SEO that meet this criteria. However, it could be used in conjunction with vulnerability 1 above or any other privilege escalation vulnerability to significantly increase an attacker’s success rate.

    Both free and Premium Wordfence users with the firewall enabled have been protected from this vulnerability since the new Firewall and Threat Defense Feed were released in April.

    What to do

    Premium Wordfence customers that have the firewall enabled are protected by the firewall rule that was added to the Threat Defense Feed on Friday, July 8th. Free Wordfence users running the Squirrly SEO plugin should upgrade to version 6.1.5 immediately, and will receive a rule to protect against vulnerability 1 on August 7th.

    The post 2 Vulnerabilities in Squirrly SEO plugin 6.1.4 and older appeared first on Wordfence.

  • Vulnerability in Profile Builder plugin 2.4.0 and older

    Wordfence Security Researcher Panagiotis Vagenas recently discovered a privilege escalation vulnerability in the Profile Builder WordPress plugin, which has over 40,000 active installs according to wordpress.org. We shared the details of the vulnerability with the author yesterday and added a firewall rule to our Threat Defense Feed. The author released version 2.4.1 today which fixes the vulnerability.

    The privilege escalation vulnerability allows an attacker to elevate the privileges of low level WordPress user roles such as Subscriber, to Administrator, giving them full control of the website. This vulnerability only impacts websites that have registration enabled, but given that the plugin functionality is directly related to registration it is likely that the majority of websites with the plugin installed are effected.

    CVSS Severity: 8.8 (High)

    What to do
    Premium Wordfence customers that have the firewall enabled are already protected by the firewall rule we added yesterday morning. Free Wordfence users running the Profile Builder plugin should upgrade to version 2.4.1 immediately, and will receive a rule to protect against this vulnerability on August 5th.

    The post Vulnerability in Profile Builder plugin 2.4.0 and older appeared first on Wordfence.

  • Realstatistics Malware Campaign Leads To Ransomware

    Realstatistics Malware Campaign Leads To Ransomware

    Our Incident Response Team (IRT) has been tracking a mass infection campaign over the last 2 weeks ( codenamed “Realstatistics“). This campaign has compromised thousands of websites built on the Joomla! and WordPress Content Management System (CMS). We have codenamed the campaign “Realstatistics” because of the domain being used by the attackers. The following fake analytics code was…

    The post Realstatistics Malware Campaign Leads To Ransomware appeared first on Sucuri Blog.