HomeSecurityCritical RCE flaws in PHP Everywhere plugin put WordPress sites at risk

Critical RCE flaws in PHP Everywhere plugin put WordPress sites at risk

Security researchers have found three critical RCE flaws in the WordPress plugin “PHP Everywhere,” which is used by over 30,000 sites worldwide. The vulnerabilities allow remote code execution.

PHP Everywhere WordPress plugin

PHP Everywhere is a plugin that allows WordPress administrators to insert PHP code into pages, posts, the sidebar, or any Gutenberg block and use it to display dynamic content.

See also: Maze/Egregor ransomware: Decryption keys released

WordPress: 3 RCE bugs in the “PHP Everywhere” plugin

Security analysts from the Wordfence discovered the bugs, which can be exploited by contributors or subscribers, and affect all versions of WordPress from 2.0.3 onwards.

See here a brief description of RCE errors:

CVE-2022-24663: A remote code execution vulnerability that could be exploited by any subscriber. The vulnerability allows them to send a request with the "shortcode" parameter set to PHP Everywhere and execute PHP code on the website. (CVSS v3 Score: 9.9)

CVE-2022-24664: Another RCE vulnerability that contributors via the plugin's metabox. An attacker could create a post, add a PHP code metabox, and then preview it. (CVSS v3 score: 9.9)

CVE-2022-24665: The third RCE vulnerability in PHP Everywhere that can be exploited by contributors who have the “edit_posts” capability and can add PHP Everywhere Gutenberg blocks. The default security setting in vulnerable versions of the plugin is not “admin-only” as it should be. (CVSS v3 score: 9.9).

See also: Fake Windows 11 upgrade installers infect you with RedLine malware

All of the vulnerabilities are considered very serious. However, the last two are a bit more difficult to exploit, as they require contributor-level privileges. The first vulnerability is much more open to wider exploitation, as it can be used by a simple subscriber.

RCE errors

For example, a connected customer on a site is considered a “subscriber,” so simply registering on the platform would be enough to gain enough privileges to execute malicious PHP code.

In all cases, executing code on a site can lead to a complete breach of the site.

The Wordfence team discovered the RCE bugs on January 4, 2022, and notified the creator of the PHP Everywhere WordPress plugin of its findings.

A update on January 10, 2022, with version 3.0.0.

See also: Mozilla Firefox: Fixes bug that granted administrator privileges

While developers patched the bugs last month, many WordPress site administrators are lagging behind in updating their sites and plugins. According to download statistics on WordPress.org, only 15,000 of the 30,000 sites using the plugin have updated.

Therefore, due to the severity of these vulnerabilities, it is recommended that all PHP Everywhere users ensure they have upgraded to version 3.0.0.

Please note that if you are using the Classic Editor on your site, you will need to uninstall the plugin and find another solution for hosting custom PHP code. This is because version 3.0.0 only supports PHP snippets via the Block editor.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS