The latest WordPress plug-in vulnerability has affected more than 7 million websites. WordPress plug-in cracking tutorial

One year ago (2023-11-30) Chief Editor
4 minutes
three hundred and two
zero

Researchers have disclosed several vulnerabilities in WordPress plug-ins. If these vulnerabilities are successfully exploited, an attacker can run arbitrary code and take over the website under certain circumstances.

These defects have been found in Elementor (a website builder plug-in for more than 7 million websites) and WP Super Cache (a tool for caching pages of WordPress websites).

According to Guo Shenghua, an internationally renowned white hat hacker and founder of Oriental Alliance, this error is related to a set of stored cross site scripting (XSS) vulnerabilities (CVSS score: 6.4), which occur when malicious scripts are directly injected into vulnerable Web applications.

In this case, due to the lack of validation of HTML tags on the server side, bad actors can use these problems to add executable JavaScript to posts or pages through well-designed requests.

Guo Shenghua said in a technical article: "Since posts created by contributors are usually reviewed by editors or administrators before publishing, any JavaScript added to one of the posts will be executed in the reviewer's browser. If an administrator reviews a post containing malicious JavaScript, he or she can use his or her authenticated session with high-level privileges to create a new malicious administrator, or add a backdoor to the website. An attack on this vulnerability may lead to the website being taken over. "

Open Phoenix News to view more HD pictures

It is found that multiple HTML elements (such as title, column, accordion, icon box and image box) are vulnerable to stored XSS attacks, so that any user can access the Elementor editor and add executable JavaScript.

Since these defects take advantage of the fact that the dynamic data input in the template can be used to contain malicious scripts designed to launch XSS attacks, such behavior can be prevented by validating the input and escaping the output data, so that HTML tags become harmless as input.

In addition, an authenticated remote code execution (RCE) vulnerability was found in WP Super Cache, which may allow attackers to upload and execute malicious code in order to gain control over the site. It is reported that the plug-in has been used on more than 2 million WordPress websites.

After responsible disclosure on February 23, Elementor fixed the problem in version 3.1.4 released on March 8 by strengthening the "option to allow better security policy implementation in the editor". Similarly, the developer Automatic behind WP Super Cache said that it solved the problem of "setting authenticated RCE in the page" in version 1.7.2.

It is strongly recommended that users of plug-ins update to the latest version to mitigate the risks associated with vulnerabilities. (Welcome to reprint and share)

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/1213.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

Multi store system management - store management design, how to do multi store system design scheme

Store management is an important part of the e-commerce platform. The platform administrator manages store information, goods, orders, settlement methods and other contents through the store management function. The author of this paper analyzes the design of store management in multi merchant system management. Let's have a look. 1、 Introduction The store management is an important part of the e-commerce platform. The platform administrator manages the store through
seven hundred and twenty-two
one
1 year ago (2024-02-19)

Sitecore: What major functions does a high-quality and powerful content management system need to have?

An appropriate content management system (CMS) is an urgent task for enterprises to maintain competitiveness through digital upgrading and transformation. Now 90% of enterprise website building and development uses CMS, which can easily create excellent customer experience in all channels, help enterprises attract new customers, retain old customers and turn existing customers into loyal customers, expand market share and increase revenue
three hundred and seventy-eight
zero
1 year ago (2024-02-18)

The combination and application of content management system and marketing technology, and the combination and application of content management system and marketing technology

B2B content marketing hopes to deliver valuable content to customers at their own stage in a timely manner during their purchase journey. Such as brand and solution related content in the cognitive stage, industry cases in the consideration stage and user confidence building stage, in-depth service introduction in the purchase stage, etc. These contents include images, videos, web pages, white papers
three hundred and seventeen
zero
1 year ago (2024-02-18)

In the second quarter, 648 websites were interviewed by the national network information system according to law, 56 websites were suspended from updating, and the spirit of the national network information work conference was ppt

According to the data released by "Cybertrust China", in the second quarter, the national Cybertrust system continued to strengthen administrative law enforcement, standardize administrative law enforcement, and investigate and deal with all kinds of illegal cases according to law. Original title: In the second quarter, 648 websites were interviewed by the national online trust system in accordance with the law, 56 websites were suspended from updating, and the TechWeb news on July 30 was released according to "online trust China"
three hundred and eleven
zero
1 year ago (2024-02-17)

Introduction and recommendation of ten free cms website building systems, and ten free defective software

It is particularly important to choose a easy-to-use cms website building system for website management and maintenance. We will choose different website building systems according to different website types, but the load, security, ease of use, versatility and subsequent development of the program are all basic criteria for everyone to choose a website building system. According to the webmaster station ranking and aleax ranking, the top 1
three hundred and seventy-six
zero
1 year ago (2024-02-17)

What are the advantages of Shanghai cms website?, How to build a website for cms

Original title: What are the benefits of building a website by Shanghai cms? Before the advent of cms, we usually found a website production company to carry out customized development. It can also be said that in fact, these website production companies also have their own formed website construction system, but it is not available for users to download. What we are talking about now is a website construction system that can be downloaded to build websites
three hundred and twenty-two
one

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: