WordPress Plugin Bug Opens 100K Websites to Compromise
#1
Information 
Quote:A high-severity cross-site request forgery (CSRF) vulnerability in Real-Time Find and Replace, a WordPress plugin installed on more than 100,000 sites, could lead to cross-site scripting and the injection of malicious JavaScript anywhere on a victim site.
 
According to research from Wordfence released on Monday, the malicious code injection could be used to create a new administrative user account, steal session cookies, redirect users to a malicious site, obtain administrative access or to infect innocent visitors browsing a compromised site with a drive-by malware attack.
 
Real-Time Find and Replace allows administrators to dynamically replace any HTML content on WordPress sites with new content without permanently changing the source content, right before a page is delivered to a user’s browser. Any replacement code or content executes anytime a user navigates to a page that contains the original content.
 
“To provide this functionality, the plugin registers a sub-menu page tied to the function far_options_page with a capability requirement to ‘activate_plugins,'” explained Wordfence researcher Chloe Chamberland, in a Monday posting. “The far_options_page function contains the core of the plugin’s functionality for adding new find-and-replace rules. Unfortunately, that function failed to use nonce verification, so the integrity of a request’s source was not verified during rule update, resulting in a CSRF vulnerability.”

Read more: https://threatpost.com/wordpress-plugin-...se/155230/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Emsisoft Anti-Malware 2025.2.0.12659
Changes in 2025.2....harlan4096 — 11:00
AVG 25.1.9816
AVG 25.1.9816: ...harlan4096 — 10:59
Avast 25.1.9816
Avast 25.1.9816: ...harlan4096 — 10:58
VeraCrypt 1.26.20
VeraCrypt 1.26.20:...harlan4096 — 10:58
UltraSearch 4.6.1.1102
UltraSearch 4.6.1....harlan4096 — 10:57

[-]
Birthdays
Today's Birthdays
avatar (45)delsreehRob
avatar (43)pyotrded
Upcoming Birthdays
avatar (46)hapedDow
avatar (45)komriwat
avatar (37)showercurtains
avatar (48)PeterWhink
avatar (49)neuthrusBub
avatar (40)oecmecodo
avatar (39)ShakitaSmobe
avatar (48)tsorenHievy
avatar (45)myhotseeve
avatar (45)Edwinmub
avatar (45)dimaWeami
avatar (40)svoyaEnuct
avatar (38)TranoTymn
avatar (38)MezirLal
avatar (49)listfquoto
avatar (45)dima6sarPrave
avatar (37)Michaelaburi
avatar (45)dpascoal
avatar (50)Ronaldduh
avatar (38)legalgauch
avatar (40)yposegij
avatar (43)Baihu
avatar (26)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>