A vulnerability successful the UpdraftPlus: WP Backup & Migration Plugin affects much than 3 cardinal WordPress websites and enables unauthenticated attackers to execute commands arsenic an administrator. The flaw makes it imaginable for attackers to upload and activate malicious plugins, which tin yet lead to distant codification execution.
UpdraftPlus Backup & Migration Plugin
The UpdraftPlus Backup & Migration Plugin is 1 of the astir wide utilized WordPress backup solutions. Website owners usage it to create backups, reconstruct websites aft problems, and migrate WordPress sites betwixt hosts, servers, and domains.
The plugin is actively installed connected much than 3 cardinal websites and supports backup retention connected a wide scope of unreality and distant services.
Vulnerable To Unauthenticated Attackers
What makes this vulnerability particularly concerning is that it does not require an attacker to log successful and nary WordPress relationship is needed to utilization the flaw. However, not each tract pinch UpdraftPlus installed is needfully exploitable successful the aforesaid way. The plugin changelog describes the affected information arsenic sites pinch an progressive Migrator cardinal aliases UpdraftCentral key.
According to the advisory, each versions up to and including type 1.26.4 are affected. The vulnerability exists successful the UpdraftPlus_Remote_Communications_V2::wp_loaded function.
The rumor is classified arsenic an authentication bypass vulnerability. Authentication bypass is simply a information flaw that enables wholly unauthenticated attackers to skip the plugin’s identity-verification and login credential checks. This gives them the expertise to return administrator-level actions without ever needing to log in, supply a password, aliases supply valid website credentials.
Authentication controls are expected to verify that commands received by the plugin are morganatic and travel from an authorized source. In this case, weaknesses successful the measurement distant communications messages are validated make it imaginable to bypass those protections.
How The Security Failure Works
The vulnerability stems from insufficient validation of the distant communications connection format.
According to Wordfence:
“The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is susceptible to Authentication Bypass successful each versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function.
This is owed to insufficient validation of the distant communications connection format, wherever signature verification tin beryllium bypassed and unchecked decryption return values illness to a predictable all-zero encryption key.
This makes it imaginable for unauthenticated attackers to forge arbitrary RPC commands and tally them arsenic the connected administrator, specified arsenic uploading and activating a malicious plugin, which yet leads to distant codification execution.”
The plugin is expected to verify that distant commands are authentic earlier executing them. The validation process tin beryllium bypassed, allowing attackers to create forged commands that the plugin treats arsenic morganatic administrator instructions. Because those commands tally pinch administrator-level privileges, attackers tin execute actions that would usually require afloat administrative access.
Also, this portion of Wordfence’s explanation needs explaining:
“This is owed to insufficient validation of the distant communications connection format, wherever signature verification tin beryllium bypassed and unchecked decryption return values illness to a predictable all-zero encryption key.”
What it intends is that the plugin has a captious coding flaw wherever a grounded encryption cheque defaults to an unfastened doorway alternatively of locking the strategy down.
Remote Code Execution
In this circumstantial context, Remote Code Execution intends an attacker tin tally malicious codification connected the website’s hosting server complete the internet.
The vulnerability enables an unauthenticated attacker to bypass authentication and forge distant commands that tally arsenic the connected administrator.
That intends an attacker tin nonstop a bid to upload and activate a malicious WordPress plugin, fundamentally creating a backdoor into the site.
Once the malicious plugin is installed and activated, the server tin execute the codification wrong that plugin. That tin alteration actions specified arsenic stealing data, adding malware, changing tract files, aliases taking power of the WordPress installation.
RCE turns the authentication bypass into a tract takeover risk. Once an attacker tin execute arbitrary codification connected the server, they tin power the affected website. This tin perchance lead to malware infections, website defacement, unauthorized administrator access, theft of delicate information, aliases the usage of the compromised tract for further attacks
The advisory specifically notes that attackers tin upload and activate malicious plugins, truthful this is simply a very existent outcome.
Evidence Of Active Attacks
Wordfence reported that it blocked 8,172 attacks targeting this vulnerability during a 24-hour period.
While onslaught activity unsocial does not bespeak really galore sites were successfully compromised, it shows that attackers are actively attempting to utilization the flaw.
Patch Available
UpdraftPlus has made a spot disposable for users to update their installations and unafraid their websites.
The plugin changelog for type 1.26.5 describes the rumor as:
“Previous versions contained a defect allowing sites pinch an progressive Migrator cardinal (paid versions only) aliases UpdraftCentral cardinal (free and paid versions) to person unauthorised operations carried retired connected them. All users should update immediately.”
Users of the UpdraftPlus: WP Backup & Migration Plugin should update to type 1.26.5 aliases a newer type arsenic soon arsenic possible.
Featured Image by Shutterstock/Toey Andante
English (US) ·
Indonesian (ID) ·