HomeSecurityWooCommerce: Plugin security flaw leads to website hijacking

WooCommerce: Plugin security flaw leads to website hijacking

A flaw in the design of WordPress allows a popular e-commerce plugin, WooCommerce, to give attackers complete control of the site. WooCommerce is an eCommerce plugin for WordPress, with which anyone can create their own online store. According to the official Plugin page on wordpress.org, there are more than 4 million active installations of the plugin.

WooCommerce plugin hijack

When plugins are installed in WordPress that do not use their own authentication method, they create new roles in the WordPress authentication system, changing the elements that each new role has access to.

According to Simon Scannell, a researcher at RIPS Tech, when WooCommerce is installed, a new role called “Shop Manager” is created that has the “edit_users” capability. With this capability, Shop Managers can change the permissions of any WordPress user, including the administrator.

Since site administrators don't want plugin users to be able to edit the Administrator account and its permissions, WooCommerce has created a feature that prevents Shop Managers from editing users who are Administrators. However, the only way to disable a plugin is to either use an Administrator account or delete the plugin files. This is where the critical security flaw was discovered!

Scannel discovered a vulnerability in WooCommerce 3.4.5, as well as in all older versions. The vulnerability exploits the plugin's ability to delete logs. What was discovered is that Shop Managers could access different folders than the ones where the logs were located, and this was done by adding the command “..” to the php argument

An example of exploiting the vulnerability is the command to delete the path: ../../plugins/woocommerce-3.4.5/woocommerce.php. With this command, the user could “go up” 2 levels into the WordPress subfolders, and delete the woocommerce.php file. By deleting woocommerce.php, the entire plugin is disabled, and the function that restricts Shop Managers stops working, giving them the ability to change the permissions of all users, including Administrators.

It should be noted that to exploit the vulnerability, the attacker would first need to have access to an account with Shop_Manager privileges. The only possible ways to do this are either through phishing, or an inside job.

Finally, the vulnerability has been fixed with version 3.4.6 of WooCommerce, which was released on October 11, which we recommend you install immediately.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS