HomeSecurityWordPress plugin bug allows subscribers to delete sites

WordPress plugin bug allows subscribers to delete sites

A critical flaw found in a WordPress plugin with more than 8,000 installations could allow authenticated attackers to restore and delete vulnerable websites. The WordPress plugin in which the flawis Hashthemes Demo Importer.

See also: Hacker sold data of millions of drivers for $800

WordPress plugin error

This is a plugin designed to help administrators import demos for WordPress themes, without having to deal with installing dependencies.

The bug could allow attackers to reset WordPress sites and delete almost all database content and uploaded media.

Wordfence engineer and threat analyst Ram Gall explained that the WordPress plugin failed to properly perform nonce checks, resulting in the AJAX nonce being leaked to all users in the dashboard of the vulnerable sites. Even low-privileged users and subscribers could access it.

See also: Google: Hackers target YouTubers with cookie theft malware

Consequently, logged-in subscriber-level users could exploit the bug to delete all content on sites running outdated versions of the Hashthemes Demo Importer WordPress plugin.

 Hashthemes Demo Importer error

Subscriber, one of the user types that could delete vulnerable sites, is a default WordPress user role (like Contributor, Author, Editor, and Administrator) that often exists on WordPress sites so that registered users can write comments in the site's comments section.

Normally, subscribers can only edit their profile using the site dashboard and do not have access to other admin pages.

The developers of Hashthemes Demo Importer had been aware of the vulnerability since August 25, 2021, however, they had not responded to Wordfence for at least a month.

See also: How a coding bug turns AirTags into malware distributors

This prompted the researchers to contact the WordPress plugins on September 20, which led to the removal of the plugin the same day and the release of a patch addressing the bug four days later (September 24).

However, the developer of Hashthemes Demo Importer did not mention version 1.1.2 or the update on the plugin's changelog page, despite the release of a security update.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS