HomeSecurityUser Submitted Posts: Vulnerability found in WordPress plugin

User Submitted Posts: Vulnerability found in WordPress plugin

A new vulnerability in the WordPress plugin “User Submitted Posts” (versions 20230902 and newer) was discovered by the Patchstack.

WordPress plugin User Submitted Posts

With over 20,000 active installations , the popular plugin is used for user -generated content submissions and is developed by Plugin Planet .

The vulnerability, which was discussed by Patchstack security researcher Rafie Muhammad , has been listed as CVE-2023-45603 .

According to the researcher, this is a vulnerability that allows unauthorized file uploads.

See also: New WordPress backdoor leads to site compromise

The flaw is related to how the plugin handles uploaded files, specifically in the “usp_attach_images” function. Unauthenticated users could exploit this vulnerability by uploading files with embedded PHP code, which would then be executed on the server, potentially compromising the security of the site.

The researcher explained that the team discovered the vulnerability in the WordPress plugin User Submitted Posts in September 2023. Plugin Planet released a patch two days later. By October 10, 2023, the vulnerability was recorded in the Patchstack database.

“Since the main problem is that arbitrary file name extensions are allowed to be uploaded, the vendor decided to add a whitelist check before uploading the file to the server,” it states.

The issue was addressed in the latest version of the WordPress plugin, version 20230914.Users are urged to upgrade immediately to protect sites .

“ Always check every $_FILES parameter in your plugin or theme code ,” the researcher wrote . “ Make sure to check the file name and extension before uploading the file .”

See also: Balada Injector attacks: 17,000 WordPress sites compromised

Website owners are also reminded to check their code for potential vulnerabilities and maintain a list of allowed file extensions, as a precautionary measure against arbitrary file uploads.

User Submitted Posts: Vulnerability found in WordPress plugin
User Submitted Posts: Vulnerability found in WordPress plugin

The security of WordPress sites is very important and potential vulnerabilities in plugins and themes can make your website vulnerable to attacks by hackers. Therefore, it is important to implement appropriate security to protect WordPress. 

Basic Safety Measures 

WordPress website administrators should take a number of basic security measures into consideration. These include choosing strong passwords ,regularly updating the software, and using a specialized antivirus tool. 

Hacking attacks 

It is crucial to know that hacker attacks are not only aimed at large companies or organizations . Entrepreneurs or individuals with a growing presence on the Internet can easily become targets.

See also: Jupiter X Core WordPress plugin: Vulnerabilities put sites at risk

Conclusion 

WordPress site security is crucial for securing your website from threats. By implementing the appropriate measures and constantly updating the software, you can ensure the security of your website and maintain a stable and reliable presence on the Internet.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS