HomeSecurityDuplicator WordPress Plugin: Error puts 1 million websites at risk!

Duplicator WordPress Plugin: Error puts 1 million websites at risk!

Duplicator WordPress Plugin: Bug puts 1 million websites at risk: The detection of vulnerable WordPress plugins seems to have not stopped recently.

New research has revealed that the Duplicator WordPress plugin is an active exploit. Duplicator is a plugin that makes it easy for website administrators to migrate WordPress sites. It also allows administrators to download files that are created after administrators create a new copy of the site.

At this point, an arbitrary download of malicious files.

Duplicator WordPress Plugin: Error puts 1 million websites at risk!

How does this happen?

The download buttons lead to a call in the WordPress AJAX handler with the action duplicator_download and a file parameter, indicating the location of the file to be downloaded. When you click the button, the required file is downloaded and the user does not need to leave or reload the current page. Unfortunately, the duplicator_download action was registered via wp_ajax_nopriv_ and was accessible to unauthenticated users.

public static function duplicator_download() { $file = sanitize_text_field($_GET['file']); $filepath = DUPLICATOR_SSDIR_PATH.'/'.$file; // Process download if(file_exists($filepath)) { // Clean output buffer if (ob_get_level() !== 0 && @ob_end_clean() === FALSE) { @ob_clean(); } header('Content-Description: File Transfer'); header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($filepath).'"'); header('Expires: 0'); header('Cache-Control: must-revalidate'); header('Pragma: public'); header('Content-Length: ' . filesize($filepath)); flush(); // Flush system output buffer try { $fp = @fopen($filepath, 'r'); if (false === $fp) { throw new Exception('Fail to open the file '.$filepath); } while (!feof($fp) && ($data = fread($fp, DUPLICATOR_BUFFER_READ_WRITE_SIZE)) !== FALSE) { echo $data; } @fclose($fp); } catch (Exception $e) { readfile($filepath); } exit; } else { wp_die('Invalid installer file name!!'); } }

 

There are no restrictions on downloaded file paths. So, it was possible for an attacker to access files in different directories by submitting values ​​like ../../../file.php. The file parameter is passed through the sanitize_text_field and appended to the plugin's DUPLICATOR_SSDIR_PATH constant, but directory traversal was still possible.

function duplicator_init() { if (isset($_GET['action']) && $_GET['action'] == 'duplicator_download') { $file = sanitize_text_field($_GET['file']); $filepath = DUPLICATOR_SSDIR_PATH.'/'.$file; // Process download if(file_exists($filepath)) { // Clean output buffer if (ob_get_level() !== 0 && @ob_end_clean() === FALSE) { @ob_clean(); } header('Content-Description: File Transfer'); header('Content-Type: application/octet-stream'); header('Content-Disposition: attachment; filename="'.basename($filepath).'"'); header('Expires: 0'); header('Cache-Control: must-revalidate'); header('Pragma: public'); header('Content-Length: ' . filesize($filepath)); flush(); // Flush system output buffer try { $fp = @fopen($filepath, 'r'); if (false === $fp) { throw new Exception('Fail to open the file '.$filepath); } while (!feof($fp) && ($data = fread($fp, DUPLICATOR_BUFFER_READ_WRITE_SIZE)) !== FALSE) { echo $data; } @fclose($fp); } catch (Exception $e) { readfile($filepath); } exit; } else { wp_die('Invalid installer file name!!'); } } } add_action('init', 'duplicator_init');

 

Exploiting this bug allowed hackers to gain access to the targeted website's database credentials. Later, attackers could potentially access the database through these credentials.

WordPress Duplicator

The following Indicators of Compromise can be used to determine if your site has been compromised.

  • Traffic recorded from this IP address is considered suspicious:

77.71.115.52

  • The attacks in this campaign are issued via GET requests with the following query strings:
action=duplicator_download file=/../wp-config.php

 

Note: Because this vulnerability can be exploited via WP AJAX, it is possible to exploit it via a POST request. In this case, it is possible to pass the action parameter in the POST body instead of the query string. This will prevent the action=duplicator_download string from appearing in the HTTP logs. However, the file parameter must be passed as a query string and is a trusted pointer.

WordPress Duplicator

Therefore, make sure you have completed the necessary updates of your WordPress site to keep it secure. According to researchers, the vulnerability affected the versions of the Duplicator plugin up to 1.3.28.

After the vulnerability, developers were notified and patched the bug with the plugin version 1.3.28. Despite the bug being fixed, about half a million websites have not updated their plugin versions. As a result, they remain exposed to attacks that exploit this flaw.

Update immediately so your website doesn't fall into the hands of hackers!

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS