HomeSecurityWordPress Royal Elementor plugin: Fixes critical vulnerability

WordPress Royal Elementor plugin: Fixes critical vulnerability

A critical vulnerability affecting the Royal Elementor Addons and Templates plugin up to version 1.3.78 appears to have been exploited by two WordPress security teams .

Since the exploit was observed before the vendor released a patch, the vulnerability is considered a zero-day.

WordPress Royal Elementor plugin

Royal Elementor Addons and Templates by 'WP Royal' is a website-building kit that allows you to quickly create web elements without any coding knowledge. According to WordPress.org, it has over 200,000 active installations.

The vulnerability is tracked as CVE-2023-5360 (CVSS v3.1:9.8 “critical”) and allows unauthenticated attackers to perform arbitrary file uploads to vulnerable websites.

See also: User Submitted Posts: Vulnerability found in WordPress plugin

Although the WordPress plugin has extension validation, to restrict uploads to only specific file types, unauthenticated users can manipulate the “ allowed list ” to bypass sanitization and checks.

This could allow attackers to perform remote code execution via the initial file, leading to a complete compromise of the vulnerable website.

Additional technical details have not been published, so as not to expand the exploitation.

According to experts, the exploit is used to create fake accounts .

Two WordPress security teams, Wordfence and WPScan (Automattic), have reported that CVE-2023-5360 has been in use since August 30, 2023, with the volume of attacks increasing since October 3, 2023.

Wordfence says it blocked more than 46,000 attacks targeting Royal Elementor last month, while WPScan has recorded 889 cases of attackers dropping ten different payloads after exploiting the vulnerability.

See also: New WordPress backdoor leads to site compromise

Most payloads used in these attacks are PHP scripts that attempt to create a WordPress administrator user named “wordpress_administrator” or act as a backdoor.

WordPress says that the majority of attacks come from just two IP addresses, so the exploit may only be known to a few threat.

WordPress sites

The WordPress plugin vendor received full details of the vulnerability on October 3 and released an updated version, Royal Elementor Addons and Templates version 1.3.79, on October 6, 2023. All users of the plugin are advised to upgrade to this version.

Please note that updating the plugin to version 1.3.79 will not automatically remove a potential infection or delete the malicious files. It protects against the exploitation of the vulnerability for future attacks. Therefore, in such cases, a site cleanup will be necessary.

See also: Balada Injector attacks: 17,000 WordPress sites compromised

WordPress Protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur. 

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies. 

Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

In other words, ensuring the security of your WordPress website isn’t just about protecting your data – it’s about maintaining customers , preserving your company’s reputation, and staying on top of the competition. 

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS