HomeSecurityWordPress: Vulnerabilities in Orbit Fox plugin allow sites to be taken over!

WordPress: Vulnerabilities in Orbit Fox plugin allow sites to be taken over!

Security experts from Wordfence have discovered two vulnerabilities in the WordPress plugin “Orbit Fox.” They are a privilege escalation vulnerability and a flaw that affect over 40,000 installations. The “Orbit Fox” plugin, which allows website administrators to add features like registration forms and widgets, is installed on over 400,000 websites.

The plugin was developed by ThemeIsle with the aim of improving the Elementor, Beaver Builder and Gutenberg editors, and implements additional features.

WordPress: Vulnerabilities in Orbit Fox plugin allow sites to be taken over!

Hackers can exploit the two vulnerabilities to inject malicious code into websites using the vulnerable version of the plugin, and take control of them.

As reported by Security Affairs, the vulnerability was rated as “critical” and received a severity rating of 9.9/10. In addition, the XSS bug allows hackers to inject JavaScript into posts. Specifically, hackers could exploit this bug to carry out multiple malicious actions, such as malicious ad attacks. The bug has been rated as “medium severity” and has received a severity rating of 6.4/10.

WordPress: Vulnerabilities in Orbit Fox plugin allow sites to be taken over!

The “Orbit Fox” plugin includes a registration widget that can be used to create a registration form with customizable fields when using the plugins . When creating the registration form, the plugin provides the ability to define a default role that will be used every time a user registers using the form.

Additionally, experts pointed out that the lack of server in Orbit Fox allows "lower-level" users (authors, editors, etc.) to set their role as an administrator upon successful registration.

Wordfence also noted that for hackers to exploit the vulnerabilities, user registration must be enabled and the website must be running the Elementor or Beaver Builder plugins.

WordPress: Vulnerabilities in Orbit Fox plugin allow sites to be taken over!

This vulnerability allowed low-level users to add malicious JavaScript to posts that would execute in the browser whenever a user browsed to that page.

Both vulnerabilities were mitigated with the release of version 2.10.3.

Vulnerabilities in WordPress plugins are very dangerous and could allow cybercriminals to carry out attacks . In December, the development team of the WordPress plugin “Contact Form 7” disclosed an “unrestricted” file upload vulnerability. This is a plugin that has over 5 million active installations.

Also in November, hackers exploited a zero-day vulnerability in the popular WordPress plugin “Easy WP SMTP” that is installed on over 500,000 sites. During the same period, hackers exploited a critical remote code in the “File Manager” plugin, resulting in over 300,000 WordPress websites being exposed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS