Online Services

Category: Security

  • Vulnerability Roundup for Thursday July 28th

    Vulnerability Roundup for Thursday July 28th

    This is a roundup of recent vulnerabilities in WordPress plugins that you should be aware of.

    This morning we published details of a reflected cross site scripting vulnerability in Easy Forms for MailChimp versions 6.1.2 and older. One of our own researchers discovered this vulnerability and notified the author who released a fix Tuesday. Upgrade immediately if you run this plugin.

    The following notable plugins have had vulnerabilities reported in the past week. If you use any of these plugins, upgrade promptly:

    Form Lightbox Plugin ScreenshotThe Form Lightbox plugin has been removed from the WordPress repository. However it contains a vulnerability that allows an attacker to update any option in the WP database, thereby gaining admin access to a site. If you use this plugin we recommend that you remove it.

    The most recent version of this plugin was version 2.1 and it had approximately 34,000 downloads at the time of it’s removal. The slug for the plugin is form-lightbox.

    Improved vulnerability alerting in Wordfence

    Note that since the 6.1.11 update of Wordfence, when you are now alerted about a plugin update, if that plugin has a known vulnerability it will be a ‘critical’ alert and if it does not have a known vulnerability the alert will be a ‘warning’. This allows you to easily differentiate between urgent plugin updates and routine.

    Summer of Pwnage

    In the past month the Dutch community project the Summer of Pwnage has uncovered multiple WordPress vulnerabilities. We encourage you to run your eye down this advisories page from the project and update any of the plugins that you run that may be affected.

    We encourage you to share these vulnerabilities with the larger WordPress community to help keep site owners safe from exploitation.

    The post Vulnerability Roundup for Thursday July 28th appeared first on Wordfence.

  • Spotlight: How iThemes Manages Their Website Security

    Spotlight: How iThemes Manages Their Website Security

    iThemes was one of the first premium theme shops for WordPress. Over the years their focus has expanded to include premium WordPress plugins that help website owners manage and secure their websites. In addition to a suite of plugins and themes, iThemes is committed to providing education and training for freelance web designers & entrepreneurs….

    The post Spotlight: How iThemes Manages Their Website Security appeared first on Sucuri Blog.

  • New Vulnerability in All in One SEO Pack Plugin 2.3.7 and earlier

    Yesterday morning Panagiotis Vagenas, a Wordfence Security Researcher, discovered a new vulnerability in the All in One SEO Pack WordPress plugin. This is in addition to another serious vulnerability we wrote about yesterday morning in the same plugin.

    As detailed yesterday, All in One SEO Pack is an extremely popular plugin with over 1,000,000 active installs. Both free and Premium Wordfence users with the firewall enabled had partial protection at the time we discovered this new vulnerability. A firewall rule that provides complete protection was added to the Threat Defense Feed yesterday morning.

    The author released version 2.3.8 which fixes the vulnerability yesterday afternoon.

    This unauthenticated stored XSS vulnerability allows an attacker to inject javascript code into a page that requires admin privileges to view. When a site admin visits the page, the malicious code that runs can perform administrative actions such as modifying existing user privileges, creating a new admin user or stealing admin session tokens.

    This exploit only works if the user has enabled the sitemap module in the plugin. We have no way of estimating the percentage of All in One SEO Pack users who are vulnerable, but given the widespread use of the plugin and the importance of sitemaps for SEO, it is likely that 100s of thousands of sites are impacted.

    CVSS Severity: 8.8 (High)

    What to do

    Premium Wordfence customers that have the firewall enabled are already completely protected by the firewall rule we added yesterday morning. Free Wordfence users running the All in One SEO Pack plugin should upgrade to version 2.3.8 immediately, and will receive a rule to completely protect against this vulnerability on August 11th.

    In addition we encourage you to share this post with the broader WordPress community to create awareness of this serious security issue.

    The post New Vulnerability in All in One SEO Pack Plugin 2.3.7 and earlier appeared first on Wordfence.

  • Serious Vulnerability in All in One SEO Pack Plugin 2.3.6.1 and earlier

    There is a serious stored cross site scripting (XSS) vulnerability in All in One SEO Pack Plugin versions 2.3.6.1 and older. This plugin is installed on over 1 million active websites and is extremely popular and widely used.

    The vulnerability allows an attacker to send a malicious HTTP User-Agent or Referrer header to the site containing an XSS payload. If the administrator then visits their admin panel and views the “Bad Bot Blocker” settings page in this plugin, the attacker can take full control of their site.

    This vulnerability is only exploitable on sites that have the “Track Blocked Bots” setting enabled. This setting is not enabled by default. We do not have definitive data to indicate how many users of the plugin have enabled this feature. However, this plugin is extremely popular:

    • All in One SEO Pack has been downloaded over 28 million times (this includes upgrades)
    • It has been around for over 9 years
    • It is one of the most downloaded WordPress plugins. Contrary to its claim of being the most downloaded WordPress plugin, Akismet, Yoast SEO and Contact Form 7 have more downloads.

    This attack has a CVSS score of 8.8 (High), however due to the extremely wide-spread use of the All in One SEO Pack plugin, we are adding this additional advisory: Wordfence rates this vulnerability as very serious because it is useful to an attacker and widely exploitable. 

    If as few as 10% of sites have the feature enabled, assuming an install base of 5 million active sites, that creates 500,000 vulnerable sites.

    What to do

    Wordfence Premium customers are already protected against exploitation of this vulnerability. We released a firewall rule to our premium customers early this morning which blocks this exploit. Our free customers will receive the rule on August 12th.

    If you are using the free version of Wordfence or are not using Wordfence at all, you will need to immediately upgrade to All in One SEO Pack Plugin version 2.3.7 which contains the fix for this security issue.

    Additional Details

    This vulnerability was discovered by David Vaartjes and you can find the full technical details of the vulnerability on his site. Congratulations David, from the Wordfence team, on unearthing this serious issue.

    A proof of concept has been published on exploit-db, which means this attack is already in the wild.

    All in One SEO Pack is made by Semper Fi Web Design.

    This story has received coverage in the past few hours from The RegisterWP Tavern, Softpedia.com and is on the IDG News Service which includes CIO.com and PCWorld.

    Timeline

    We encourage you to share this post with the larger WordPress community to create awareness of this security issue.

    The post Serious Vulnerability in All in One SEO Pack Plugin 2.3.6.1 and earlier appeared first on Wordfence.