Online Services

Blog

  • XSS Vulnerability in Wordfence 6.1.1 to 6.1.6. Severity: 6.1 (Medium)

    An hour ago a security researcher, Kacper Szurek, reported a reflected XSS vulnerability in the current version of Wordfence. Wordfence is now using CVSS as our standard vulnerability scoring mechanism. The severity of this vulnerability is 6.1 (Medium).

    Impact

    This only affects Wordfence users who have the Wordfence firewall disabled. Wordfence has built in protection against XSS vulnerabilities and has had since version 6.1.1, so if your firewall is enabled you are not affected. If you have the firewall in learning mode or disabled, you are not protected against this vulnerability.

    What to do

    We have already released a fix. If you have Wordfence set to auto-update then it will automatically update to Wordfence 6.1.7 within the next 24 hours and you don’t have to take any action. If you have the Wordfence firewall enabled, you are already protected and were never affected by this issue.

    If you have Wordfence auto-update disabled and you have the firewall in learning mode or disabled, we recommend you sign into your website and manually upgrade Wordfence to version 6.1.7 now. We also suggest that you consider enabling your Wordfence firewall if that is feasible for you.

    Vulnerability Info

    CVSS Severity: 6.1

    CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

    Vulnerability Type: Reflected XSS (Cross Site Scripting)

    Kacper has shared a proof of concept for this vulnerability with us which we have verified. We will not be sharing it at this time but may share it at a future date.

    Further notes on vulnerability disclosure by Wordfence

    At Wordfence we practice responsible disclosure both on products belonging to other vendors and on our own product. Even though this is our own product, you will see a style of disclosure here that uses the same standards that we use when we disclose vulnerabilities relating to other vendor’s products.

    Wordfence has now standardized on using the CVSS 3.0 vulnerability scoring system which we have included in this post. Going forward we will include the CVSS score of every vulnerability in the subject of our blog posts and in an email alert we send to our community. This gives our community an immediate indication at a glance of the severity of a vulnerability. It also provides an objective methodology of scoring vulnerabilities that is not subject to opinion or bias.

     

    The post XSS Vulnerability in Wordfence 6.1.1 to 6.1.6. Severity: 6.1 (Medium) appeared first on Wordfence.

  • Vulnerability in Yoast SEO 3.2.4 for WordPress

    One of our security researchers, Panagiotis Vagenas, discovered a vulnerability in Yoast SEO version 3.2.4 and earlier that allows any user with ‘subscriber’ level access to download your Yoast SEO settings. For sites that have open registration, this means that anyone can register and download your Yoast SEO settings by simply creating an account and running the exploit.

    We reported this vulnerability to Yoast Tuesday May 3rd and their team has released a fix today, Friday May 6th. We recommend that you upgrade immediately if you are using Yoast SEO. This vulnerability is fixed in Yoast SEO version 3.2.5.

    If you are using Wordfence Premium, you have been protected against this vulnerability being exploited from the moment we notified the plugin author which was on Tuesday. We released a firewall rule via the Threat Defense Feed on Tuesday that is already protecting your site. This is per our standard disclosure procedure. See below for details.

    Details of the Vulnerability

    Yoast SEO plugin has a Sensitive Data Exposure vulnerability. Plugin registers the following AJAX actions:

    wpseo_export
    get_focus_keyword_usage
    get_term_keyword_usage

    These actions are privileged therefore are available only to registered users, but no special capabilities are required to perform them. Any user with a valid account to the target website can exploit those actions to get information about Yoast SEO settings and post metadata relative to focus and terms keywords.

    This kind of information should be available only to users with administrative capabilities. To be more precise, to users that have the manage_options capability, because the plugin’s option pages require this capability by default.

    We will not be releasing an exploit proof of concept at this stage but we shared a PoC with the Yoast team on Tuesday to help them confirm and fix the vulnerability.

    Wordfence Standard Disclosure Procedure

    At Wordfence the security of our customers and the greater WordPress community is of paramount importance to us. With this in mind we have developed standard disclosure procedures when we discover a vulnerability that are as follows:

    1. One of our research team discovers a vulnerability and shares it with the rest of the team who verifies the vulnerability.
    2. We develop a Firewall rule to protect our customers. This rule is obfuscated to prevent reverse engineering.
    3. We notify the vendor and simultaneously release a firewall rule to protect our premium customers via the Threat Defense Feed. Customer sites are updated immediately with the rule and no customer action is required.
    4. Vendor releases a fix, usually after several days and we announce the existence of the vulnerability at the same time to encourage the community to upgrade.
    5. Wordfence community (free) customers receive the firewall rule 30 days after the initial release to Premium customers.
    6. At a future date we may release a PoC so that other firewall providers can create rules to protect their customers too.

    The post Vulnerability in Yoast SEO 3.2.4 for WordPress appeared first on Wordfence.

  • Ninja Forms Shell Upload Vulnerability – Very High Risk

    A few times a year we see very bad vulnerabilities come along. This is, unfortunately, one of those times.

    Ninja Forms versions 2.9.36 to 2.9.42 contain multiple vulnerabilities. One of the vulnerabilities results in an attacker being able to upload and execute a shell on WordPress sites using Ninja Forms. We have developed a working exploit for internal use at Wordfence. The only information the exploit needs is a URL on the target site that has a form powered by Ninja Forms version 2.9.36 to 2.9.42.

    Wordfence Firewall already protects against uploading of malicious PHP files, so you were already protected against this attack while it was still a 0 day. As an additional precaution, this morning we have released three additional rules via the Wordfence Threat Defense Feed which are already active on our Wordfence Premium customer sites.

    Ninja Forms has over 500,000 active installs, so the impact of this vulnerability is going to be fairly wide-spread.

    We are monitoring attacks in real-time and are not yet seeing this being widely exploited yet. We suspect this is because an exploit has not shown up yet on exploit-db or other public exploit databases (as of 9am Pacific time on May 5th). We expect this to happen within 48 hours and there will almost immediately be widespread attacks that exploit this vulnerability.

    It’s not often that attackers are provided with a fresh vulnerability in a popular plugin that lets them drop shells or execute code on a large number of WordPress sites. This only happens a few times a year.

    WordPress.org has already released an automated forced plugin update. This happened on May 3rd which was 48 hours ago. We’ve confirmed that this forced update is taking effect on our test sites. This vulnerability will continue to affect sites that have not been updated by their owners and where forced plugin update is disabled or not feasible.

    What to Do

    1. Update Ninja Forms immediately to at least version 2.9.45 if you haven’t already.
    2. If you are running the free version of Wordfence you already have fairly good protection against this vulnerability.
    3. If you are running our Premium version, we have already released new rules that give you full protection against this vulnerability even if your site has not been updated yet.
    4. If you aren’t using our firewall but are using a competing product, verify that they protect against this specific exploit. This is a new vulnerability and they may not have added rules to protect against it yet.
    5. If you weren’t using a firewall before you updated you should also verify that your site has not already been compromised. We recommend you install Wordfence and run a scan.

    You can find the full disclosure of the vulnerability by James Golovich on pritect.net. This was published yesterday and contains more technical detail of the vulnerability.

    You can find Ninja Forms changelog here which will help you keep abreast of any additional security updates they may release in the next few days.

     

    The post Ninja Forms Shell Upload Vulnerability – Very High Risk appeared first on Wordfence.

  • WordPress Redirect Hack via Test0.com/Default7.com

    WordPress Redirect Hack via Test0.com/Default7.com

    We’ve been working on a few WordPress sites with the same infection that randomly redirects visitors to malicious sites via the default7 .com / test0 .com / test246 .com domains. In this post, we’ll provide you with a review of this attack, investigated by our malware analyst, John Castro. Header.php Injection In all cases, the
    Read More

    The post WordPress Redirect Hack via Test0.com/Default7.com appeared first on Sucuri Blog.