HomeSecurityWordPress plugin flaw allows hackers to turn users into administrators

WordPress plugin flaw allows hackers to turn users into administrators

A critical privilege escalation flaw found in a WordPress SEO plugin, Rank Math, could allow hackers to grant administrator privileges to any user registered on one of the 200,000 sites with active installations, if they haven’t been patched. Rank Math is a WordPress plugin described by developers as “the Swiss Army Knife of WordPress SEO” and is designed to help site owners drive more traffic to their sites through search engine optimization (SEO). The plugin comes with a setup wizard that walks you through a step-by-step installation process and features support for Google Schema Markup (also known as Rich Snippets), keyword optimization, Google, Google keyword position tracking, and more.

The privilege escalation vulnerability was discovered in Rank Math by Defiant’s Wordfence Threat Intelligence team in an unprotected REST API. According to Defiant QA engineer Ram Gall, successful exploitation of this flaw allowed an unauthenticated attacker to update arbitrary metadata, which included the ability to grant or revoke administrator privileges for any user logged into the site. Worse yet, hackers could also “lock” administrators out of their sites by revoking their administrator privileges, seeing as how many WordPress sites have only one user as an administrator.

WordPress plugin flaw allows hackers to turn users into administrators

Researchers discovered a second flaw in the REST API endpoint that allowed unauthenticated attackers to create redirects from almost any location on a site to any destination they wanted. The flaw was found in one of the optional modules of the Rank Math plugin that helps users create redirects on WordPress websites. According to Ram Gall, this attack could be used to block access to all existing content on a site, except for the homepage, by redirecting visitors to a malicious site.

In late March, the development team released Rank Math 1.0.41, an update containing fixes for REST API security issues reported by the Defiant. Since at least one of these two bugs is considered critical, it is highly recommended that Rank Math users get the latest update 1.0.41.2 which contains fixes for both bugs.

WordPress plugin flaw allows hackers to turn users into administrators

Since early 2020, WordPress websites have been heavily targeted by hackers, who are trying to take them over by exploiting recently fixed or zero-day vulnerabilities in plugins installed on hundreds of thousands of sites. In late February, researchers identified tens of thousands of attacks on WordPress websites that exploit critical vulnerabilities and could create malicious accounts .

Hackers also attempted to compromise WordPress websites by exploiting vulnerable connections with approximately 1,250,000 active installations, as well as multiple bugs in a WordPress plugin, GDPR Cookie, used by more than 700,000 websites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS