HomeSecurityStored XSS detected in popular WordPress plugin Jetpack

Stored XSS detected in popular WordPress plugin Jetpack

The XSS vulnerability affects the contact form module of the popular plugin, allowing arbitrary code execution in the WordPress backend.

jetpack

Sucuri, a cybersecurity company, has identified a persistent XSS (cross-site scripting) vulnerability in one of the most popular WordPress plugins, Automattic's Jetpack plugin.

[signoff icon=”icon-target”]Jetpack is a WordPress plugin developed by Automattic, the company behind WordPress.com, which also oversees the development of the open-source WordPress content management system. The plugin is extremely popular, with over 1 million downloads.[/signoff]

During his regular research into popular WordPress plugins, Sucuri researcher Marc-Alexandre Montpas discovered a glitch in the way email addresses are satinized in Jetpack's contact form module.

This module allows you to add contact forms to any page or post, using a button that is added to the native WordPress WYSIWYG editor.

 

The discovered XSS vulnerability affects Jetpack version 3.7, as well as earlier versions.

As Mr. Montpas points out, this vulnerability affects version 3.7, as well as earlier versions of Jetpack, and is remotely exploitable, without requiring a high level of technical knowledge. Furthermore, according to Sucuri's DREAD vulnerability severity rating system, the vulnerability is classified as highly critical, ranking 8th out of 10 overall in the rating system.

To successfully exploit this particular XSS bug, a specially crafted email string is required which, once submitted, ends up in the WordPress database.

Every time the administrator of a vulnerable WP page navigates to the Feedback section of the admin panel, the email string is executed, allowing the attacker to run malicious code inside the WordPress backend.

“An attacker could use this bug and some of the web browser hackery […] to perform all sorts of malicious actions (inserting a backdoor for future exploitation on vulnerable websites, executing arbitrary code, etc.), the researcher says.

[alert variation=”alert-success”]Sucuri submitted its findings to Automattic on September 10th, and the development team fixed the XSS bug in Jetpack version 3.7.1.[/alert]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS