Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

WordPress Delayed Disclosure of Critical Vulnerability

WordPress has disclosed a critical privilege escalation vulnerability patched on January 26 with the release of version 4.7.2. The developers of the content management system (CMS) said they wanted to make sure users were protected against potential attacks before making the details public.

WordPress has disclosed a critical privilege escalation vulnerability patched on January 26 with the release of version 4.7.2. The developers of the content management system (CMS) said they wanted to make sure users were protected against potential attacks before making the details public.

When it announced the release of version 4.7.2, WordPress said the latest version patched three vulnerabilities, including SQL injection, cross-site scripting (XSS) and access control issues.

However, it turns out that WordPress 4.7.2 also addresses a severe privilege escalation flaw that can be exploited to hijack websites. Fortunately, there is no evidence that the weakness has been exploited in the wild.

The security hole, discovered by researchers at Sucuri, has been described by WordPress developers as an unauthenticated privilege escalation vulnerability in a REST API endpoint. The flaw affects WordPress websites running versions 4.7.0 and 4.7.1.

By sending a specially crafted request, an unauthenticated attacker can change the content of any post on the targeted website. Next, they can add plugin-specific shortcodes and exploit other flaws that would normally be restricted to users with elevated privileges. An attacker can also abuse the compromised website for SEO spam, to inject ads, and even execute PHP code, depending on which plugins are enabled.

In a blog post published on Wednesday, WordPress Core Contributor Aaron D. Campbell explained that the disclosure of the vulnerability was delayed by one week to give websites time to update their installations.

Sucuri’s Marc-Alexandre Montpas reported the vulnerability to WordPress on January 20 and a fix was created shortly after. While the patch was being tested by developers, Sucuri configured its Web Application Firewall (WAF) to block exploitation attempts and WordPress reached out to companies such as SiteLock, Incapsula and CloudFlare so that they could protect their customers as well. WordPress hosts were also notified and provided instructions on how to protect users.

“Data from all four WAFs and WordPress hosts showed no indication that the vulnerability had been exploited in the wild,” Campbell said. “As a result, we made the decision to delay disclosure of this particular issue to give time for automatic updates to run and ensure as many users as possible were protected before the issue was made public.”

Advertisement. Scroll to continue reading.

Related: Over 8,800 WordPress Plugins Have Flaws

Related: Brute Force Attacks on WordPress Websites Soar

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...