Online Services

Category: Security

  • 2 Vulnerabilities in Squirrly SEO plugin 6.1.4 and older

    Today the Squirrly SEO team released version 6.1.5 of their WordPress plugin, fixing two security vulnerabilities. They have over 20,000 active users according to wordpress.org. Panagiotis Vagenas, Security Analyst here at Wordfence discovered the vulnerabilities. Details were shared with the author and firewall rules were added to the Wordfence Threat Defense Feed on Friday. The path traversal and privilege escalation vulnerabilities impact versions 6.1.4 and older.

    Vulnerability 1: Privilege Escalation

    CVSS Severity: 8.8 (High)

    This vulnerability allows an attacker to modify plugin settings on a site with registration enabled. On a stand-alone basis the value to an attacker is relatively low, enabling them to do things like add or change the site favicon, upload featured images for posts or retrieve SEO settings for a post. As you’ll see below, the real danger with this vulnerability is when it is used in conjunction with another.

    Vulnerability 2: Path Traversal

    CVSS Severity: 8.1 (High)

    This vulnerability allows an attacker to download any file from a WordPress server, including the wp-config.php file. That file includes database credentials for the website and other information that could potentially enable an attacker to gain full control of the site. In order to exploit this vulnerability there are two conditions that must be met: a specific plugin parameter must be set to a specific value and a favicon must be present. We have no way of estimating the percentage of websites running the Squirrly SEO that meet this criteria. However, it could be used in conjunction with vulnerability 1 above or any other privilege escalation vulnerability to significantly increase an attacker’s success rate.

    Both free and Premium Wordfence users with the firewall enabled have been protected from this vulnerability since the new Firewall and Threat Defense Feed were released in April.

    What to do

    Premium Wordfence customers that have the firewall enabled are protected by the firewall rule that was added to the Threat Defense Feed on Friday, July 8th. Free Wordfence users running the Squirrly SEO plugin should upgrade to version 6.1.5 immediately, and will receive a rule to protect against vulnerability 1 on August 7th.

    The post 2 Vulnerabilities in Squirrly SEO plugin 6.1.4 and older appeared first on Wordfence.

  • Vulnerability in Profile Builder plugin 2.4.0 and older

    Wordfence Security Researcher Panagiotis Vagenas recently discovered a privilege escalation vulnerability in the Profile Builder WordPress plugin, which has over 40,000 active installs according to wordpress.org. We shared the details of the vulnerability with the author yesterday and added a firewall rule to our Threat Defense Feed. The author released version 2.4.1 today which fixes the vulnerability.

    The privilege escalation vulnerability allows an attacker to elevate the privileges of low level WordPress user roles such as Subscriber, to Administrator, giving them full control of the website. This vulnerability only impacts websites that have registration enabled, but given that the plugin functionality is directly related to registration it is likely that the majority of websites with the plugin installed are effected.

    CVSS Severity: 8.8 (High)

    What to do
    Premium Wordfence customers that have the firewall enabled are already protected by the firewall rule we added yesterday morning. Free Wordfence users running the Profile Builder plugin should upgrade to version 2.4.1 immediately, and will receive a rule to protect against this vulnerability on August 5th.

    The post Vulnerability in Profile Builder plugin 2.4.0 and older appeared first on Wordfence.

  • Realstatistics Malware Campaign Leads To Ransomware

    Realstatistics Malware Campaign Leads To Ransomware

    Our Incident Response Team (IRT) has been tracking a mass infection campaign over the last 2 weeks ( codenamed “Realstatistics“). This campaign has compromised thousands of websites built on the Joomla! and WordPress Content Management System (CMS). We have codenamed the campaign “Realstatistics” because of the domain being used by the attackers. The following fake analytics code was…

    The post Realstatistics Malware Campaign Leads To Ransomware appeared first on Sucuri Blog.

  • 3 Vulnerabilities in WP Maintenance Mode plugin 2.0.6 and older

    This morning an update to the WP Maintenance Mode plugin, version 2.0.7, was released which included fixes for 3 security vulnerabilities. According to wordpress.org the plugin is very popular, with over 400,000 active users.  The vulnerabilities were discovered by Sean Murphy, Sr. Developer at Wordfence, and we notified the plugin author last week. A firewall rule was added to the Threat Defense Feed at the time of author notification.

    The most serious of the vulnerabilities which impacts WordPress sites with registration enabled, allows an attacker to download a list of subscriber email address from the database. Another vulnerability allows an attacker to modify plugin settings. The WP Maintenance Mode plugin was temporarily removed from the plugin repository during the past week in order to fix these vulnerabilities. It has now been restored.

    Vulnerability 1: Information Disclosure

    CVSS Severity: 4.3 (Medium)

    This vulnerability allows a remote attacker to download the list of subscribers from WP Maintenance Mode who have asked to be notified when a site returns to full functionality. To exploit this vulnerability, an attacker simply needs to have a registered account on the victim site with no special permissions.

    Vulnerability 2: Missing Authorization

    CVSS Severity: 4.3 (Medium)

    This vulnerability allows an attacker with a subscriber level account to modify plugin settings.

    Vulnerability 3: Remote Code Execution

    CVSS Severity: 9.1 (Critical)

    We’d like to caveat the CVSS score in this case with the description below. The CVSS score for this vulnerability is very high due to the way CVSS calculates vulnerability severity. This is a ‘critical’ vulnerability, but please read the description in the next paragraph to fully understand it’s impact.

    WP Maintenance Mode allows unsanitized user input to be evaluated as PHP code. In WordPress Multisite, a site administrator could exploit this vulnerability to execute shell commands, access sensitive information, escalate privileges or cause denial of service. To be clear: This means that on a multisite installation of WordPress, a site administrator which only has access to a single site in a network of several websites, can exploit their way to network admin and also gain access to the underlying server to fully control all sites in the network.

    To exploit this vulnerability, you have to have ‘site admin’ access to a WordPress multi-site installation. Therefore we don’t expect this vulnerability to have a widespread impact, even though the CVSS score is high. However, we would like to note its severity because if a Network admin encounters a malicious site admin, it can have a severe impact.

    What to do

    Premium Wordfence customers with the firewall enabled have been protected since last week by the firewall rule that was added when we notified the vendor.

    Free Wordfence users who are running the WP Maintenance Mode plugin should upgrade to version 2.0.7 immediately. Our free users will receive the rule to protect against this vulnerability 30 days after our premium customers received the rule – approximately 3 weeks from now.

    The post 3 Vulnerabilities in WP Maintenance Mode plugin 2.0.6 and older appeared first on Wordfence.