WordPress announced a information merchandise 7.0.3 to hole 12 vulnerabilities, 3 of which look to beryllium reasonably serious, pinch 1 vulnerability rated 8.9/10 High.
Twelve WordPress Vulnerabilities In Core
In the past it’s been comparatively uncommon for vulnerabilities to beryllium discovered successful WordPress but precocious location person been an different cluster of vulnerability discoveries, aided by AI.
There are 12 vulnerabilities and the charismatic WordPress announcement only provides the bare minimum explanation of what they are and zero severity information, making it difficult for the mean WordPress users to understand the urgency and value of the patches.
These are the 12 vulnerabilities:
- A Contributor+ stored cross-site scripting (XSS) rumor successful the Post Date block
- A Contributor+ stored cross-site scripting (XSS) rumor successful the Post Content block
- An accusation disclosure rumor successful the Latest Comments artifact exposing comments connected password-protected posts
- A bypass of the email reside confirmation flow
- An Author+ CSS injection rumor via a bypass of the safe CSS property filter
- A Contributor+ stored cross-site scripting (XSS) rumor successful posts via the emoji settings element
- A privilege escalation rumor connected multisite networks pinch personification registration enabled, allowing a personification to create a caller site
- A server-side petition forgery (SSRF) rumor successful URL validation allowing requests to link-local ranges
- A pre-auth reflected cross-site scripting (XSS) rumor connected the login surface pinch imaginable to lead to PHP codification execution
- A disclosure of notes successful remark feeds
- An enumeration of station slugs
- A Contributor+ stored cross-site scripting (XSS) rumor successful Quick Edit connected sites pinch a ample number of users
Of those, 3 are astir apt of the highest/higher concern:
- Pre-auth XSS connected the login surface pinch imaginable PHP codification execution
This is confirmed to beryllium rated arsenic a precocious severity vulnerability. - SSRF allowing requests to link-local ranges
This is perchance superior but location is nary accusation astir it correct now to cognize for certain. SSRF intends Server-Side Request Forgery. For this context, link-local IP ranges are IP addresses that are reserved for soul connection wrong the server. Put each that together and the minimal explanation of this vulnerability implies that the vulnerability enables server-side requests to link-local IP ranges which tin expose delicate accusation connected the server. But location is nary explanation of this vulnerability, truthful we tin only infer from the bare accusation given. - A privilege escalation rumor connected multisite networks pinch personification registration enabled, allowing a personification to create a caller site.
This vulnerability enables the unauthorized expertise to create different tract connected the network. That could beryllium an rumor for organization sites for illustration universities but besides to those pinch multisite installations.
High Severity Rated XSS Vulnerability
Quite apt the astir concerning vulnerability successful the database is the 1 described arsenic a Pre-Auth XSS. XSS intends Cross-Site Scripting.
The Open Worldwide Application Security Project (OWASP) describes XSS for illustration this:
“Cross-Site Scripting (XSS) attacks are a type of injection, successful which malicious scripts are injected into different benign and trusted websites. XSS attacks hap erstwhile an attacker uses a web exertion to nonstop malicious code, mostly successful the shape of a browser broadside script, to a different extremity user. Flaws that let these attacks to win are rather wide and hap anyplace a web exertion uses input from a personification wrong the output it generates without validating aliases encoding it.
An attacker tin usage XSS to nonstop a malicious book to an unsuspecting user. The extremity user’s browser has nary measurement to cognize that the book should not beryllium trusted, and will execute the script. Because it thinks the book came from a trusted source, the malicious book tin entree immoderate cookies, convention tokens, aliases different delicate accusation retained by the browser and utilized pinch that site.”
Pre-auth XSS connected the login surface pinch imaginable PHP codification execution
That’s rated 8.9/10. That vulnerability is branded arsenic “Pre-auth” which intends that an attacker does not request a WordPress relationship to motorboat an attack, but that’s mitigated to a definite grade because the exploitation still requires personification interaction, personification pinch an relationship connected the tract needs to beryllium tricked into performing an action (aka societal engineering).
The charismatic WordPress GitHub security repo explains this vulnerability says that it tin lead to distant codification execution (RCE):
“WordPress is susceptible to a pre-auth reflected XSS vulnerability connected the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is imaginable for this to beryllium escalated to an RCE vulnerability pinch conditions extracurricular of the attackers control. This requires successful societal engineering of and definitive relationship by the target victim.
This rumor affects each versions of WordPress. Version 7.0.3 has been released, containing a hole for the vulnerability, and arsenic a courtesy to users connected older branches the hole has been backported to each branches backmost to 4.7.”
Oliver Sild of Patchstack tweeted connected X astir the XSS vulnerability:
“Weeks agone erstwhile #WP2Shell dropped and OpenAI Sol Ultra took astir of the in installments – each I thought astir was really each the different labs and AI-pentest companies will unreserved to beryllium they tin find thing successful the WordPress halfway too.
Well, today, 3 weeks later – we person the adjacent WordPress halfway type merchandise pinch not one, but 12 vulnerabilities being patched. And arsenic expected, the issues person been reported by @AnthropicAI, @pwn_ai, @AikidoSecurity, and others.
The nastiest 1 is simply a login surface XSS, which via immoderate societal engineering could lead to Remote Code Execution. Luckily, WordPress is auto-updating accelerated and nary of the vulnerabilities are mass-exploitable for illustration WP2Shell was.
As always, @patchstackapp customers received mitigation rules correct astatine the disclosure.”
Oliver Sild besides told MCP that they’re search if hackers are exploiting the XSS vulnerability:
“We’re search whether it’s getting exploited, but looks for illustration the societal engineering spot connected the XSS that could lead to RCE is astir apt not going to get overmuch attraction from the hackers.”
Featured Image by Shutterstock/Jihan Nafiaa Zahri
English (US) ·
Indonesian (ID) ·