Online Services

Category: Security

  • Ask Wordfence Episode 1: Setting Up Minimum Viable WordPress Security

    Last week we emailed a small group of our customers asking them to contribute questions for a series of videos we will be running. We received questions from many of you, so thank you very much for participating!

    Today we are publishing Episode 1 of “Ask Wordfence,” where we discuss one of the questions we received: how to set up minimum viable security for WordPress.

    You can watch the episode here on the blog, or find it on YouTube.com. Remember to hit “subscribe” on the video on YouTube if you would like to view the rest of the videos in the series.

    As always, I welcome your comments below.

    The post Ask Wordfence Episode 1: Setting Up Minimum Viable WordPress Security appeared first on Wordfence.

  • 3 Zero-Day Plugin Vulnerabilities Being Exploited In The Wild

    As part of our site cleaning service, our security analysts track down the method the attacker used to compromise the site. Often this involves quite a bit of investigative work, and recently it led us to find 0-day exploits in three separate plugins. The exploits were elusive: a malicious file seemed to appear out of nowhere, and even sites with access logs only showed a POST request to /wp-admin/admin-ajax.php at the time the file was created. But we captured the attacks in our threat data, and our lead developer Matt Barry was able to reconstruct the exploits. We quickly pushed new WAF rules to block these exploits. Premium customers received the new rules and were protected immediately. We also notified the plugin authors; all three have published updates to fix the vulnerabilities.

    PHP Object Injection Vulnerability Severity 9.8 (Critical) in Appointments, RegistrationMagic-Custom Registration Forms, and Flickr Gallery

    Affected plugins and versions:

    This vulnerability allowed attackers to cause a vulnerable website to fetch a remote file (a PHP backdoor) and save it to a location of their choice. It required no authentication or elevated privileges. For sites running Flickr Gallery, the attackers only had to send the exploit as POST request to the site’s root URL. For the other two plugins, the request would go to admin-ajax.php. If the attacker was able to access their backdoor, they could completely take over the vulnerable site.

    CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

    What To Do

    If you are running the Premium version of Wordfence and have the firewall enabled, our new firewall rules are already protecting you. Free users of Wordfence and paid users who have the Wordfence firewall disabled and are running these plugins should update to the most recent versions immediately.

    The post 3 Zero-Day Plugin Vulnerabilities Being Exploited In The Wild appeared first on Wordfence.

  • Fake Plugins, Fake Security

    Fake Plugins, Fake Security

    Fake Plugins, Fake Security

    WordPress users are becoming increasingly more aware of security threats and as a result they are taking more actions to secure their websites (e.g. by installing security plugins). While this is a good thing, there are always black hats trying to take an advantage of new opportunities to compromise websites. For example, we’re seeing a rising number of fake plugins claiming to offer security, when in reality they have malicious intentions.

    Recently, a fake WordPress security plugin called X-WP-SPAM-SHIELD-PRO got our attention.

    Continue reading Fake Plugins, Fake Security at Sucuri Blog.

  • Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1

    Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1

    Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1

    During regular research audits for our Sucuri Firewall (WAF), we discovered a source-based stored Cross-Site Scripting (XSS) vulnerability affecting WordPress 4.8.1.

    Are You at Risk?

    The vulnerability requires an account on the victim’s site with the Contributor role – or any account in a WordPress installation with bbPress plugin, as long as it has posting capabilities (if anonymous posting is allowed then no account is needed).

    Continue reading Stored Cross-Site Scripting Vulnerability in WordPress 4.8.1 at Sucuri Blog.