HomeSecurityWordPress plugin flaw allows malicious code to be inserted

WordPress plugin flaw allows malicious code to be inserted

The WordPress Builder Popup plugin has a vulnerability that allows the insertion of malicious JavaScriptinto popups, which can appear on tens of thousands of websites and steal sensitive information or even take complete control of a website.

Popup Builder enables website owners to create, deploy, and manage customized popups that feature a wide range of content from HTML and JavaScript code, to images and videos.

The creator of this add-on, Sygnoos, presents it as a tool that can help increase sales and revenue, through smart popups, to display ads, subscription requests, discounts, and various other types of promotional content.

WordPress plugin flaw allows malicious code to be inserted

The errors discovered

As discovered by Defiant QA Engineer, Ram Gall, bugs affect all versions up to Popup Builder 3.63.

"Typically, attackers use such a vulnerability to redirect website visitors to malvertising sites or to steal sensitive information from their browsers, although it could also be used to take over the website if an administrator visited or previewed a page containing the infected popup while logged in."

Another bug discovered allows any logged in user (with subscriber privileges) to access plugin functions, export newsletter subscriber lists, as well as export system configuration information with a simple POST request to admin-post.php.

The flaws were designated as CVE-2020-10196 and CVE-2020-10195 and allow unauthenticated XSS storage, configuration disclosure, user data extraction, and modification of website settings.

Sygnoos fixed the security issues in version 3.64.1 of Popup Builder, a week after the bugs were reported by Defiant.

So far 66,000 websites are still exposed to attacks.

Since late February, many hackers have been trying to exploit vulnerabilities in WordPress plugins to install backdoors and create accounts that will allow them to expose thousands of accounts to attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS