22 Nov 2023

300,000+ Install Widgets for Google Reviews WordPress Plugin Doesn’t Contain a High Risk Arbitrary File Upload Vulnerability

One of the ways we keep track of possible vulnerabilities in WordPress plugins is to monitor the WordPress Support Forum for discussions related to those. Today, there was a concerning claim of a high risk vulnerability in a plugin that is used by at least one of our customers, as well aa 300,000+ websites, Widgets for Google Reviews. Another user of the plugin was claiming that it contained a “high risk vulnerability as it allows the upload of backdoors”. They also said this was an arbitrary file upload vulnerability. They were not the original source for the claim, instead, it was Patchstack.

Patchstack’s own claims were similar. They, for example, wrote that the claimed vulnerability would “allow a malicious actor to upload any type of file to your website”. It’s only if you click a button labeled “Show technical details” that they bothered to mention a critical detail. The attacker, they say, would need to have the WordPress Editor role or above to exploit this. [Read more]