2 Aug 2022

Hacker Probably Targeting This Authenticated Option Update Vulnerability in Make’s WordPress Plugin

Yesterday we had what appeared to be a hacker probing for usage of the Make’s (formerly Integromat) WordPress plugin on our website with the following request:

/wp-content/plugins/integromat-connector/assets/iwc.js [Read more]

18 Jul 2022

Hacker Exploiting Unfixed Vulnerability in WooCommerce Extending Plugin MultiSafepay

The security of plugins that extend the WordPress ecommerce plugin WooCommerce is often poor, something that the developer of WooCommerce, Automattic, hasn’t taken an interest in addressing. Another part of Automattic claims to provide some protection against that, but isn’t delivering that. Automattic’s WPScan is promoted with this claim:

Be the first to know about vulnerabilities affecting your WordPress installation, plugins, and themes. [Read more]

3 Jun 2022

Jupiter X Core Plugin Still Contains Vulnerability Allowing Reverting Website Database to Previously Backed Up Version

As detailed in more detail in a security advisory we have released for the developer of the plugin Jupiter X Core, recently the developer left 90,000+ websites open to being hacked for two weeks, after the WordPress security company Wordfence disclosed an easily exploited vulnerability in the plugin where there wasn’t a fix available (while claiming to have done responsible disclosure). Once the new version of the plugin that addressed that was released, we could check over the current state of the plugin. What we found was that Wordfence hadn’t warned people that the plugin still contains many vulnerabilities.

Wordfence explained how to exploit the vulnerability this way: [Read more]

2 Jun 2022

Hacker Targeted WooCommerce Payment Plugin From Openpay Allows Anyone to Change Payee Setting

On Monday we had what appeared to be a hacker probing for usage of the Openpay Payment Gateway plugin (not to be confused with BBVA’s Openpay plugins) for WooCommerce with the following request:

/wp-content/plugins/opy-paymentplugin-woocommerce/README.md [Read more]

27 May 2022

Our Proactive Monitoring Caught a CSRF/PHP Object Injection Vulnerability in 1+ Million Install WordPress Plugin Ninja Forms

One way we help to improve the security of WordPress plugins, not just for our customers of our service, but for everyone using them, is our proactive monitoring of changes made to plugins in the Plugin Directory to try to catch serious vulnerabilities. Late last year we expanded on that for our customers, by running plugins used by our customers, even when code in them is not updated, through the same system on a weekly basis. We just made a significant improvement to the automated portion of that monitoring. Through that, we caught a less serious variant of one of those vulnerabilities, a cross-site request forgery (CSRF)/PHP object injection vulnerability in Ninja Forms. Which, besides being used by at least one of our customers, is used on 1+ million websites according to wordpress.org’s stats.

That Ninja Forms has yet another vulnerability isn’t surprising considering the developer’s security track record, which includes disclosing a fairly serious unfixed vulnerability last year (doing that alongside Wordfence) and still not having addressed an incorrect security fix, which we notified them about in January. [Read more]

25 May 2022

600,000+ Install WordPress Plugin WP Statistics Isn’t Properly Securing Its Optimization Functionality

Yesterday the JVN released a vague report claiming that a cross-site scripting (XSS) vulnerability had been fixed in version 13.2.0 of the WordPress plugin WP Statistics. There isn’t enough information provided to confirm that there was a vulnerability or that it was fixed.

Confusingly, one of our competitors, Automattic’s WPScan, is citing that report as the source for a claim that a vulnerability was fixed in version 13.2.2 of the plugin: [Read more]

24 May 2022

Recently Closed WordPress Plugin with 40,000+ Installs Contains Minor Defacement Vulnerability

Yesterday, the WordPress plugin Shapely Companion was closed on WordPress Plugin Directory. Because that is one of the 1,000 most popular plugins in that directory (it has 40,000+ installs), our systems warned us about the closure and we started checking over the plugin to see if there was a vulnerability we should warn customers of our services about. What we found was that it at least contains a minor vulnerability.

The plugin registers the function shapely_companion_import_content() to be accessible through WordPress’ AJAX functionality by anyone logged in to WordPress: [Read more]

19 May 2022

Contempo Real Estate Custom Posts WordPress Plugin Contains Authenticated Arbitrary File Upload Vulnerability

Last week the there was what looked to be a hacker probing for usage of the WordPress plugin Contempo Real Estate Custom Posts in third-party data we monitor, by requesting this file:

/wp-content/plugins/contempo-real-estate-custom-posts/readme.txt [Read more]

18 May 2022

Hacker Probably Targeting This Authenticated Arbitrary File Upload Vulnerability in WP ERP

Earlier this week Wordfence got press coverage for a situation where they were obliquely admitting they were way behind hackers. As they were claiming to have started seeing attacks against a vulnerability in a WordPress plugin on May 10, while publicly available data from the website abuseipdb.com was showing attacks at the end of March. On Monday data we monitor from that website showed that what looked to be a hacker probing for usage of the WordPress plugin WP ERP by requesting this file from it:

/wp-content/plugins/erp/readme.txt [Read more]