HomeSecurityZero-day vulnerabilities revealed in Facebook's WordPress plugins

Zero-day vulnerabilities revealed in Facebook's WordPress plugins

plugins

Two of Facebook 's official WordPress plugins are affected by two zero-day vulnerabilities , which were disclosed by an American cybersecurity firm.

The company also presented proof-of-concept (PoC) code, which reveals how hackers can exploit these vulnerabilities to carry out attacks on sites.

The two affected plugins are “Messenger Costumer Chat”, which displays a custom Messenger on WordPress sites, and “Facebook for WooCommerce”, which allows WordPress site owners to upload WooCommerce-powered stores to their Facebook Pages.

In mid-April, WordPress decided to release the Facebook for WooCommerce plugin as part of the official plugin for the online WooCommerce store. Since then, the plugin has gathered an overall rating of 1.5 stars, with the overwhelming majority of users complaining about bugs and incomplete updates.

However, now the security of all users who installed these extensions is at risk due to a dispute between a Denver-based company called White Fir Design LLC (doing business as Plugin Vulnerabilities) and WordPress.

The Plugin Vulnerabilities team decided that it would not follow the policy change on the WordPress.org forums, which prohibited users from disclosing security flaws through the forums and asked security researchers to send them electronically to the WordPress team, so that it could communicate with those who used the plugins.

However, the Plugin Vulnerabilities team continued to disclose security vulnerabilities on the WordPress forums, and as a result its forum accounts were blocked.

Their rivalry escalated over time, and last spring the team began also publishing blog posts on its website with details and PoC code regarding the vulnerabilities it discovered in WordPress plugins.

The hackers, of course, did not miss the opportunity and, using the information posted by Plugin Vulnerabilities, began creating malicious campaigns, some of which managed to affect large sites.

The two flaws discovered in Facebook's plugins allow certified users to modify the WordPress site options. The vulnerabilities are not as dangerous as those revealed earlier this year, however they could allow an attacker to take control of a website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS