WordPress theme plug-in serious vulnerability repair, affecting nearly 200000 websites, WordPress intrusion tools

4 minutes
three hundred and nine
zero

The developers of the ThemeGrill Demo Importer program of WordPress have updated the plug-in, removing a serious vulnerability that provides administrator privileges for unauthenticated users. The attacker can log in as an administrator and restore the entire database of the website to its default state, thus fully controlling these websites.

This plug-in is used to easily import ThemeGrill theme presentation content, gadgets and settings, making it easier for them to quickly customize the theme. The plug-in is currently installed on nearly 200000 WordPress websites, and the most popular version is most vulnerable to attacks.

The vulnerability exists in the ThemeGrill Demo Importer plug-in from 1.3.4 to 1.6.1. According to the statistics of the official WordPress plug-in repository, the most popular versions are 1.4 to 1.6, accounting for more than 98% of the current installation.

The ThemeGrill theme must be in a valid state to erase the database of infected websites. The plug-in is installed, which makes it possible for criminals to attack.

Researchers from WebARX, a WordPress security company, remind that there is also a prerequisite for an administrator account to log in automatically and quickly. The target database has the user "admin". WebARX network security company mainly provides vulnerability detection and virtual patch software, so that websites can avoid the impact of errors in third-party components.

Once the plug-in detects the installed ThemeGrill theme and activates it, it will load the file/includes/class-demo-importer.php, which attaches reset_wizard_actions to admin_init in line 44.

The researcher explained that the hook of "admin_init" runs in the management environment, and can also call "/wp admin/admin ajax. php" of users who do not need to be authenticated.

Lack of authentication makes vulnerability exploitation possible. If there is an "admin" user in the database, an unauthenticated attacker may use this account to log in and delete all WordPress tables that begin with the defined database prefix.

Once all tables have been deleted, it will populate the database with default settings and data, and then set the password of the "admin" user to its previously known password.

WebARX researchers found the vulnerability on February 6 and reported it to developers on the same day. Ten days later, on Sunday, ThemeGrill released a new version to fix the vulnerability.

At the time of writing this article, the number of plug-in downloads after patching was about 23000, which indicates that a large number of websites using ThemeGrill Demo Importer may still be in danger.

In mid January, two vulnerabilities were reported for WordPress Database Reset. When these vulnerabilities are exploited, they will have the same impact as this event. WordPressDatabase Reset is a convenient method for administrators to reset administrators to default values.

One CVE-2020-7048 allows unauthenticated users to reset tables from any database, while the other CVE-2020-7047 grants account administrator privileges with the least privileges.

(Reprinted from FreeBuf. COM)

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/964.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

Industry Fit! Preferred element of WMS warehouse management system, wms warehouse software

Enterprise managers often think that warehouses are inefficient, high cost places, and belong to heavy asset operations. With the development of enterprise business, if the warehouse needs to be expanded in traditional ways, the cost is relatively high. At the same time, it also faces problems such as lack of operating experience. In the operation link, the process of warehouse, allocation, human resource matching and management is very complicated, and the team's professional ability is also highly required
seven hundred and eighty-three
zero
1 year ago (2024-02-19)

Supply chain billing system management (I): system overview, what are the supply chain management fees

In recent years, with the continuous development of e-commerce industry and increasing business, everyone has started to distribute goods online, and the supply chain billing system needs to manage more and more things. How to manage the billing system? The author summarizes some contents about settlement based on his own practical experience, hoping to enlighten you. After working on the warehouse management system for several years, I was transferred to work as a supplier
five hundred and fifty-four
zero
1 year ago (2024-02-19)

Multi merchant system management - store background design, what is the meaning of multi merchant classification

Simply understood, multi merchants are a large mall. The platform can manage merchants who settle in the mall. The merchants who settle in the mall have independent backstage. They can log in and add goods to the shelves by themselves, manage stores by themselves and other information functions. Then how to design the backstage of the store? Let's see the author's sharing. I hope it can help you. 1、 Introduction The backstage of the store is an important part of the e-commerce platform
six hundred and forty-six
zero
1 year ago (2024-02-19)

Jiangyang District of Luzhou City took the lead in the city's full coverage training on domestic waste classification management regulations, Luzhou waste treatment

Source: Original Draft On January 10, the People's Congress of Jiangyang District, Luzhou City and the District Government jointly carried out a training on the regulations of the Regulations on the Classified Management of Domestic Waste in Luzhou City (the Regulations for short), and invited Lei Zhengyun, the chairman of the Legislative Affairs Committee of the Municipal People's Congress, to give a live lecture, so as to guide the comprehensive and systematic grasp of the contents and legal functions and responsibilities of the Regulations, deeply understand the specific specifications of the Regulations, and quickly set off
three hundred and seventeen
zero
1 year ago (2024-02-19)

Simeng CMS (smcms) content management system, Simeng Central Primary School

SMCMS (Simon CMS) is a content management system developed based on the microbee http rapid development framework. Product development follows the concept of simplicity, security, high concurrency and efficiency. Enterprise level web content management software for high-end users is designed to help users solve the increasingly complex and important web content creation, maintenance, publishing and response
three hundred and sixty-one
zero
1 year ago (2024-02-19)

Does the website have to install a content management system?, What apps are needed to install software on the website

1: The role of the website is to let companies or enterprises display their own windows, but also to let more customers or potential customers know their work and products. Through the website, customers can understand their products and services more intuitively, and can also provide more services to meet customer needs. 2: The role of the content management system The content management system can help
four hundred and fifty-six
zero

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: