Two serious vulnerabilities in Post Grid, a WordPress plugin with more than 60,000 installations, open the door to attack. For starters, nearly identical bugs are also found in Post Grid's sister plugin, Team Showcase, which has 6,000 installations.
The bugs are an XSS, as well as a PHP injection issue. Both bugs have pending CVE numbers, and both are high severity, with a rating of 7.5 out of 10 on the CvSS vulnerability rating scale.

Post Grid, true to its name, allows users to display their posts in a grid layout. Meanwhile, Team Showcase offers a way to easily highlight an organization’s team members. Both allowed for the introduction of custom layouts and used nearly identical — and vulnerable — functionality to do so, according to Ram Gall, a researcher at Wordfence.
The XSS bug could allow an attacker to provide a parameter pointing to a malicious payload hosted elsewhere. The function would then open the file containing the payload, decode it, and create a new page layout based on its contents.
"The generated layout included a custom_scripts section , and an attacker could add malicious JavaScript to the custom_css section of that section. This would then be executed whenever an admin user edited the layout or a visitor visited a page based on the layout."
The result is that Post Grid attackers could use malicious JavaScript to add a malicious admin, a backdoor to plugins or theme files, or steal the admin's session information – all of which are routes to completing a site takeover.
"In both cases, an incoming attacker with minimal privileges, such as the subscriber, could trigger the features by sending an AJAX, with the action set to post_grid_import_xml_layouts for Post Grid or team_import_xml_layouts for Team Showcase, with each action triggering a feature with the same name," Gall explained.
The second issue, the PHP, occurs in the import function because it did not capture the payload provided in the source parameter. An attacker could therefore execute arbitrary code, delete or write files, or even perform any number of other actions that could lead to a website takeover.
To trigger the flaw, "an attacker could create a string that could not be sterilized into an active PHP object. Although no plugin used vulnerable magic methods, if another plugin was installed that used a vulnerable magic method, "object injection" could be used by an attacker.
Both vulnerabilities typically require the attacker to have an account with at least subscriber-level privileges – but there is a loophole.
"However, websites that use a plugin or theme that allows unauthorized visitors to execute arbitrary shortcuts will be vulnerable to unauthorized attackers," Gall added.
The plugin developer, PickPlugins, has released patches, so webmasters should upgrade as soon as possible. The stable versions are Post Grid v. 2.0.73 and Team Showcase v. 1.22.16.

These are the latest in a series of flawed WordPress plugins to surface this year. In September, a severe bug in the “Email Subscribers and Newsletters” plugin from Icegram was found to affect more than 100,000 WordPress sites.
Earlier in August, a plugin designed to add quizzes and surveys to WordPress sites returned two critical vulnerabilities. The flaws could be exploited by remote, unauthenticated attackers to launch a variety of attacks — including complete takeover of vulnerable sites. Also in August, Newsletter, a WordPress plugin with more than 300,000 installations, was discovered to have a pair of vulnerabilities that could lead to code execution, and even site takeover.
It should be noted that researchers in July warned of a critical vulnerability in a WordPress plugin called Comments – wpDiscuz, which was installed on more than 70,000 websites. The flaw allowed unauthorized attackers to upload arbitrary files (including PHP files) and ultimately execute remote code on vulnerable website servers.
