Vulnerabilities found in the Newsletter plugin leave 300,000 sites exposed to hackers. In particular, WordPress website owners who use the Newsletter plugin are advised to update installations to prevent attacks in which hackers could exploit a fixed vulnerability, install backdoors, create “rogue administrators” and potentially take over their sites. Specifically, the vulnerability was found in WordPress’ Newsletter plugin, which provides the tools needed to create responsive newsletter and email marketing campaigns on WordPress blogs, using a visual composer.
It is worth noting that the Newsletter has already been downloaded over 12 million times since it was added to the official WordPress repository and is now installed on over 300,000 sites.

Wordfence’s Threat Intelligence group published a report in which cyber threat analyst Ram Gall said he discovered two more vulnerabilities while analyzing a previous patch released by the plugin’s creators on July 13. Specifically, Wordfence identified a Cross-Site Scripting (XSS) security flaw and a PHP Object Injection vulnerability. Both of these vulnerabilities were fully patched by the Newsletter development team on July 17, with the release of version 6.8.3, two days after the initial report sent on July 15. While these two vulnerabilities are rated as moderate and high severity that could allow hackers to add “rogue administrators” and install backdoors after successfully exploiting the XSS flaw on sites running vulnerable versions of the Newsletter plugin.

Additionally, the PHP Object Injection vulnerability could be used to inject a PHP object that can be used for arbitrary code, file uploads, or other tactics by which hackers could take over a site.
Although Newsletter 6.8.3, the version of the plugin that fixed the two vulnerabilities, was released on July 17, the plugin has only been downloaded 151,449 times since then. This means that at least 150,000 WordPress websites with active Newsletter installations could remain vulnerable to potential attacks if hackers start exploiting these vulnerabilities in future campaigns.

Newsletter users are urged to update their plugin to version 6.8.3 as soon as possible to prevent attacks in which hackers could install “rogue administrators” or install backdoors on their sites, as they already frequently use patched WordPress plugin vulnerabilities in their attacks. For example, two months ago, Wordfence reported a campaign that targeted hundreds of thousands of WordPress websites within 24 hours, aiming to collect database credentials by stealing configuration files, after successfully exploiting XSS vulnerabilities affecting WordPress plugins and themes.

Between May 29 and May 31, 2020, Wordfence Firewall blocked over 130 million attacks aimed at collecting database credentials from 1.3 million sites by downloading their configuration files, according to what Gall said at the time.
Last week, a critical vulnerability discovered in the wpDiscuz plugin, which is installed on over 70,000 WordPress websites, allowed hackers to take over hosting accounts via remote code execution attacks.
