HomeSecurityVulnerabilities in Multidots e-commerce plugins for Wordpress

Vulnerabilities in Multidots e-commerce plugins for WordPress

Researchers have discovered vulnerabilities and security holes in 10 WordPress plugins made by e-commerce plugin company Multidots. WordPress removed many of them after their developers failed to patch the holes.

Vulnerable Multidots e-commerce plugins for WordPress

ThreatPress announced Thursday that its researchers discovered several vulnerabilities in plugins from Multidots. The plugins were available through WordPress.org, and allowed store owners to customize their sites to their liking. There were nearly 20,000 total active installations at the time the plugins were removed from the store, and among them were applications such as page visit counter, Woocommerce Category Banner management and Checkout for digital goods.

What the researchers discovered is that all of their applications are vulnerable to cross-site scripting (XSS), cross-site request forgery (CSRF), and SQL injection, through which hackers could insert keyloggers, secretly implement crypto-miners, remotely execute code, or even take full control of the site. This means they could also access sensitive user data such as stored card details, as the aforementioned plugins are used by online stores.

“The vulnerabilities allow unauthorized users to inject malicious code via JavaScript, allowing them to steal information from potential customers, card details, or credentials from administrators,” ThreatPress said.

Multidots was notified of the vulnerabilities on May 8 and confirmed them. However, it was unable to patch the flaws, and the majority of the affected plugins were removed after ThreatPress reported them to WordPress.

“It’s nice to know that WordPress can react quickly to issues like this, but there’s still a big problem. There’s no way to notify all active users about the plugins that were removed.”

“It’s strange that WordPress displays information about all available updates from installed applications, but doesn’t have a similar feature for malicious ones that have been removed for security reasons. We hope to see such a feature soon as for Multidots applications alone we could save almost 20,000 websites!”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS