Showing posts with label Wordpress. Show all posts
Showing posts with label Wordpress. Show all posts

Thursday, September 5, 2013

XSS in BackWPup WordPress plugin HTB23161

BackWPup version 3.0.12 (WordPress plugin) is vulnerable to perform cross-site scripting (XSS) attacks against administrator of website. The vulnerability exists due to insufficient filtration of user-supplied data in "tab" HTTP GET parameter passed to "wp-admin/admin.php" script. A remote attacker can trick a logged-in administrator to open a specially crafted link and execute arbitrary HTML and script code in browser in context of the vulnerable website.

Full details and how-to exploit XSS vulnerability on BackWPup example available here. Solution: upgrade your installation to BackWPup 3.0.13.

Saturday, August 17, 2013

Duplicator WordPress Plugin cross-site scripting XSS vulnerability

Duplicator WordPress Plugin Duplicator WordPress Plugin version 0.4.4 is vulnerable to perform cross-site scripting / XSS attack because insufficient filtration of user-supplied data in "package" HTTP GET parameter passed to "wp-content/plugins/duplicator/files/installer.cleanup.php" script exist. This attack can be exploited against a logged-in administrator to steal login cookies. Upgrade to Duplicator version 0.4.5 to be safe from this vulnerability in this plugin for WP.

Additional details provided here: www.htbridge.com/advisory/HTB23162.

Thursday, February 7, 2013

HTB23140: Wysija Newsletters WordPress plugin SQL injection vulnerability

Wysija Newsletters

Wysija Newsletters WordPress plugin version 2.2 suffer from SQL injection vulnerability (HTB23140), which can be exploited to perform SQL Injection attacks.

The vulnerabilities exist due to insufficient filtration of user-supplied input passed via the "search" and "orderby" HTTP GET parameters to the "wp-admin/admin.php" script. A remote authenticated administrator can execute arbitrary SQL commands in application's database. This vulnerability could also be exploited by a remote non-authenticated attacker via CSRF vector, since the application is prone to cross-site request forgery attacks.

Upgrade to Wysija Newsletters version 2.2.1 to fix this vulnerability.

Wednesday, February 6, 2013

HTB23138: CommentLuv WordPress plugin cross-site scripting (XSS) vulnerability

CommentLuv WordPress plugin

Cross-site scripting (XSS) vulnerability was discovered by High-Tech Bridge Security Research Lab in CommentLuv WordPress plugin 2.92.3, which can be exploited by a malicious people to perform attacks. The vulnerability exists due to insufficient filtration of user-supplied data in "_ajax_nonce" HTTP POST parameter in the "wp-admin/admin-ajax.php" script.

CommentLuv is a popular WordPress plugin that will magnetize your readers, socialize your comments and viralize your posts.

For solution upgrade to CommentLuv 2.92.4

Thursday, April 12, 2012

HTB23083: CMS Tree Page View Plugin for WordPress XSS vulnerability

CMS Tree Page View (WordPress plugin) version 0.8.8 suffers from cross-site scripting (XSS) vulnerabilities:
Input passed via the "cms_tpv_view" GET parameter to "wp-admin/options-general.php" script is not properly sanitised before being returned to the user.

Vulnerability ID: HTB23083
Vendor Notification / Patch / Public Disclosure Dates: 21 March / 26 March / 11 April
Vulnerabilities Type: Cross-Site Scripting (XSS)
Solution Status: Fixed by Vendor
Risk level: Medium
Solution: Upgrade to 0.8.9 or later version

HTB23082: All-in-One Event Calendar Plugin for WordPress multiple XSS vulnerabilities

All-In-One Event Calendar (WordPress plugin) version 1.4 suffers from multiple cross-site scripting (XSS) vulnerabilities:
Input passed via the "title" GET parameter to "wp-content/plugins/all-in-one-event-calendar/app/view/agenda-widget-form.php", "args", "title", "before_title", "after_title" GET parameters to "wp-content/plugins/all-in-one-event-calendar/app/view/agenda-widget.php", "button_value" GET parameter to "wp-content/plugins/all-in-one-event-calendar/app/view/box_publish_button.php", "msg" GET parameter to "wp-content/plugins/all-in-one-event-calendar/app/view/save_successful.php" scripts are not properly sanitised before being returned to the user.

Vulnerability ID: HTB23082
Public Disclosure: April 11, 2012
Vulnerabilities Type: Cross-Site Scripting (XSS)
Risk level: Medium