Tag

Vulnerabilities

  • CSRF Vulnerability Found in Software License Manager Plugin

    CSRF Vulnerability Found in Software License Manager Plugin

    Versions before 4.5.1 of the Software License Manager plugin for WordPress have an exploitable Cross-Site Request Forgery (CSRF) vulnerability. We recommend to upgrade the plugin as soon as possible.

  • Malware using the REST API for Remote Code Execution

    Malware using the REST API for Remote Code Execution

    In this post we cover an example of a malware using the REST API to allow bad actors to run remote code on the server.

  • Arbitrary Role Change/Privilege Escalation in HM Multiple Roles WordPress plugin

    Arbitrary Role Change/Privilege Escalation in HM Multiple Roles WordPress plugin

    While investigating a security advisory about an arbitrary role change/privilege escalation issue in the HM Multiple Roles WordPress plugin, the Jetpack Scan team discovered that the fix was incomplete and left the plugin still vulnerable. The issue is fully fixed in version 1.3 of the plugin, and we advise any sites using any earlier version…

  • Severe Vulnerability Patched In WooCommerce Currency Switcher

    Severe Vulnerability Patched In WooCommerce Currency Switcher

    During an internal audit of the woocommerce-currency-switcher plugin, we uncovered a very severe local file inclusion vulnerability. This security flaw could enable attackers to leak sensitive information like database credentials, cryptographic keys, and may allow arbitrary code execution in some instances. We reported the vulnerabilities to the WOOCS team via email last week, and they…

  • Multiple vulnerabilities in Workreap theme by Amentotech

    Multiple vulnerabilities in Workreap theme by Amentotech

    Recently the Jetpack team found some infected files in one of our hosted customers’ sites, and quickly traced the source of infection back to the Workreap theme by Amentotech. We started an investigation and uncovered a number of vulnerable AJAX endpoints in the theme; the most severe of these was an unauthenticated unvalidated upload vulnerability…

  • Fake Plugin Alert: WordPress Plugin and User Backup Tool

    Fake Plugin Alert: WordPress Plugin and User Backup Tool

    Attackers are abusing compromised accounts to install a fake WordPress plugin called: WordPress Plugin and user backup Tool.

  • Vulnerabilities Found in Motor WordPress Theme < 3.1

    Vulnerabilities Found in Motor WordPress Theme < 3.1

    During an audit of the Motor theme (full name “Motor – Cars, Parts, Service, Equipments and Accessories WooCommerce Store” by Stockware) for WordPress, we found a number of rather severe vulnerabilities. These vulnerabilities would allow an unauthenticated attacker complete read access to files on the file system of the site host, and would also allow…

  • Vulnerable Kaswara Modern WPBakery Page Builder Addons Plugin Being Exploited in the Wild

    Vulnerable Kaswara Modern WPBakery Page Builder Addons Plugin Being Exploited in the Wild

    Back on April 20th, 2021, our friends at WPScan reported a severe vulnerability on Kaswara Modern VC Addons, also known as Kaswara Modern WPBakery Page Builder Addons. It is not available anymore at Codecanyon/Envato, meaning that if you have this running, you must choose an alternative. This vulnerability allows unauthenticated users to upload arbitrary files to…

  • What to Do if Infected With SEO Spam on WordPress

    What to Do if Infected With SEO Spam on WordPress

    At Jetpack, dealing with different types of web threats and attacks is part of our routine. Most of the time, it ranges from collecting a malicious file and finding the attack vector, to providing assistance on restoring a website from the latest backup. But sometimes we enter a different dimension of really creative attacks, a…

  • Vulnerabilities Found in Patreon WordPress plugin

    Vulnerabilities Found in Patreon WordPress plugin

    During an internal audit of the Patreon plugin for WordPress, the Jetpack Scan team found several weak points that would allow someone to take over a website.