WordPress found few vulnerabilities: Know how to fix them


Team Udayavani, Aug 1, 2021, 12:32 PM IST

Two vulnerabilities have been found in the WordPress plugin that was installed on over 1,00,000 websites. WordPress Download Manager, the plugin is used to change how download pages are displayed.

The Wordfence Threat Intelligence team found the vulnerabilities.

WordPress Download Manager has some protections in place to protect against directory traversal, they did not prove to be sufficient in this particular case, leading to a contributor with lower privileges being able to retrieve the contents of a site’s wp-config.php file by adding a new download and performing a directory traversal attack.

The contents of the wp-config.php were visible in the page’s source code upon previewing the download and as the contents of the file were echoed out onto the page source, a user with author-level access could also upload a file or multimedia containing malicious JavaScript and set the contents of the file to the path of the uploaded file which could result in Stores Cross-Site Scripting.

Earlier, the WordPress Download Manager team had patched a vulnerability that allowed users to upload files with php4 extensions as well as other potentially malicious files. But reports stated that this patch protected many configurations, it only checked the last file extension that made it possible for an attacker to carry out a “double extension” attack by uploading a file with multiple extensions like info.php.png.

Website owners who use WordPress are advised to update to the latest version immediately as the WordPress team and developers have released a patch.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Mangaluru: 2 arrested for peddling ganja at Moodushedde

Delhi Metro launches WhatsApp-based ticketing service on Airport Line

Karnataka govt enhances DA for its employees from 31% to 35%

Curious case of Saha’s WTC Final omission baffles many

No water supply for 2 days in select areas of Mangaluru from June 2

Gurugram woman duped of Rs 1.8 crore by Nigerian ‘friend’

Maharashtra farmers to get Rs 6,000 a year under new scheme approved by Cabinet

Related Articles More

Worst cyberattack in Greece disrupts high school exams, causes political spat

Delhi Metro launches WhatsApp-based ticketing service on Airport Line

Third of Milky Way’s most common planets could harbour life: Study

China successfully launches new manned spaceship with first civilian on board

China to send astronauts to Moon by 2030 as space race intensifies

MUST WATCH

Tribe people in brhills

An accident between cars on National Highway 66, four injured

Natana Rangashaale | Udayavani

Jagadish shettar defeated Basavaraj bommai in 1994

Vinaya Kumar Sorake submission of nomination papers-Kapu


Latest Additions

Mangaluru: 2 arrested for peddling ganja at Moodushedde

Will do a film when emotionally ready: Aamir Khan

NCERT drops references to Khalistan demand from class 12 political science textbook

Can’t force citizen to choose between education and reproductive autonomy, says Delhi HC

Worst cyberattack in Greece disrupts high school exams, causes political spat