Online Services

Blog

  • Vulnerability fixed in Jetpack 4.0.3. Severity: 6.1 (Medium)

    An XSS vulnerability has been fixed in Jetpack version 4.0.3 which was released yesterday. If you haven’t automatically been updated to Jetpack 4.0.3 please update immediately. The CVSS score we have calculated for this vulnerability is 6.1 (Medium).

    If you are running the Wordfence firewall, we have verified with our own proof-of-concept attack that you are already protected against this exploit.

    Jetpack parses HTML looking for objects like Vimeo links. If it finds a Vimeo link or similar object it tries to be helpful and turn it into the Vimeo embedded video code. The trouble with the vulnerable version of Jetpack is that it doesn’t check if the link isn’t already surrounded by potentially malicious HTML tags.

    The attack that this vulnerability enables is a stored cross site scripting attack or ‘stored XSS’. It allows an attacker to include malicious javascript in comments which execute within site visitor and site owner’s web browsers.

    The fix released by the Jetpack team enhances the filtering that is performed on incoming comments.

    The Akismet team has already released a fix for this which prevents malicious comments from being posted. They are filtering out comments that contain the malicious payload that exploits this vulnerability.

    The WordPress security team are pushing security hotfixes that will fix this issue. This issue affects the following versions of Jetpack: Versions: 2.0.7, 2.1.5, 2.2.8, 2.3.8, 2.4.5, 2.5.3, 2.6.4, 2.7.3, 2.8.3, 2.9.4, 3.0.4, 3.1.3, 3.2.3, 3.3.4, 3.4.4, 3.5.4, 3.6.2, 3.7.3, 3.8.3 and 3.9.7.

    If you are using Wordfence firewall (free or paid) you are already protected against this exploit because Wordfence has built in protection against stored XSS attacks. 

    If you haven’t updated to Jetpack 4.0.3 then please update now.

    Jetpack have posted a detailed blog post about the vulnerability.

    They have also included a helpful FAQ.

    The post Vulnerability fixed in Jetpack 4.0.3. Severity: 6.1 (Medium) appeared first on Wordfence.

  • Security Advisory: Stored XSS in Jetpack

    Security Advisory: Stored XSS in Jetpack

    During regular research audits for our Sucuri Firewall (Cloud-based WAF), we discovered a stored XSS vulnerability affecting the WordPress Jetpack plugin, currently installed on more than a million WordPress sites. The vulnerability can be easily exploited via wp-comments and we recommend everyone to update asap, if you have not done so yet. Vulnerability Disclosure Timeline:…

    The post Security Advisory: Stored XSS in Jetpack appeared first on Sucuri Blog.

  • 3 Plugin Vulnerabilities Disclosed Yesterday

    We disclosed three plugin vulnerabilities yesterday that we’d like to bring to your attention to.

    Local File Inclusion Vulnerability Severity 4.2 (Medium) and Unauthorized Options Update Vulnerability Severity 4.4 (Medium) in WP Fastest Cache

    Wordfence Security Researcher Panagiotis Vagenas discovered both of these vulnerabilities in the WP Fastest Cache plugin which we reported to the author yesterday. The Local File Inclusion vulnerability allows an attacker to execute code on the target web server or on a site visitor’s browser. This enables the attacker to steal or manipulate data, perform a denial of service attack or enable additional attack types such as Cross Site Scripting. Wordfence Firewall provided protection against this type of attack prior to discovery.

    The Options Update vulnerability allows an attacker to access and make changes to the CDN (Content Delivery Network) options for the website. With this control an attacker can direct all requests for css files, images, videos, etc. to their site, allowing them to serve malicious content to visitors of the vulnerable site.

    Local File Inclusion CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

    Options Update CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

    What to do

    If you are running the Premium version of Wordfence and have the firewall enabled you are already protected because we added protection for both vulnerabilities yesterday.

    Free Wordfence users running this plugin should update the vulnerable plugin immediately. Paid Wordfence users who have the firewall disabled should also update the vulnerable plugin immediately. The author released a fix within an hour of our notifying him of this vulnerability.

    Sensitive Data Exposure Vulnerability Severity 4.3 (Medium) in Caldera Forms

    Wordfence Security Researcher Panagiotis Vagenas also discovered this vulnerability, which we reported to the Caldera Forms author yesterday. This vulnerability allows an attacker to gain access to potentially sensitive data that has been captured by a Caldera Form.

    CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

    What to do

    If you are running the Premium version of Wordfence and have the firewall enabled you are already protected, we added a firewall rule yesterday. Free users of Wordfence and paid users who have the Wordfence firewall disabled who are running this plugin should update to the most recent version immediately. The author released a fix within hours of discovery and published a blog post about it this morning.

    The post 3 Plugin Vulnerabilities Disclosed Yesterday appeared first on Wordfence.

  • Nulled WordPress Themes: Malvertising and Black Hat SEO

    Nulled WordPress Themes: Malvertising and Black Hat SEO

    If you have been following our blog for some time, you know that we regularly warn about risks associated with the use of third-party software on your site. A benign plugin may sneakingly inject ads into your site which cause malvertising problems for the site visitors (e.g. SweetCaptcha). Other plugins may be hijacked by hackers or…

    The post Nulled WordPress Themes: Malvertising and Black Hat SEO appeared first on Sucuri Blog.