Saturday, March 8, 2025
HomeVulnerability1,000,000 WordPress Websites Affected with OptinMonster Vulnerabilities

1,000,000 WordPress Websites Affected with OptinMonster Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

Multiple vulnerabilities were discovered recently by the Wordfence Threat Intelligence team in OptinMonster, it’s a popular WordPress plugin that is already installed on more than 1,000,000 WordPress Websites.

The vulnerabilities identified in OptinMonster allow an attacker to export sensitive data, put malicious JavaScript onto the vulnerable WordPress sites, and do many other actions remotely.

In short, these multiple vulnerabilities allow unauthorized API access to sensitive data on more than a million websites on the platform.

Flaw profile

On September 28, the primary flaw is tracked as CVE-2021-39341, which was discovered by researcher Chloe Chamberland, and a fix was made available on October 7 in version 2.6.5 of the plugin.

While here below we have mentioned the flaw profile with all the key details:-

  • CVE ID: CVE-2021-39341
  • Affected Plugin: OptinMonster
  • Description: Unprotected REST-API to Sensitive Information Disclosure and Unauthorized app.optinmonster.com API access
  • Plugin Slug: optinmonster
  • CVSS Score: 7.2 (High)
  • Affected Versions: <= 2.6.4
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • Fully Patched Version: 2.6.5

API issue

OptinMonster makes use of APIs for the full functioning of its integration with other services since it helps site owners convert visitors to subscribers/customers through beautiful opt-in forms.

API allows the creation of platforms in a more manageable and more practical way for the developers. So, the implementation of these assemblies in OptionMonster is not always reliable.

If there is a critical flaw in the process then it can expose the sensitive data to the operators without any authorization like:-

  • API keys
  • Path of communicating servers

On the OptinMonster accounts, an attacker having the API key can make changes and also establish malicious JavaScript snippets on the vulnerable websites. 

Even all the REST-API endpoints that are registered in the plugin was vulnerable to authorization bypass flaw. However, among them, the /wp-json/omapp/v1/support’ endpoint s the worse one.

Here, to access the API endpoint the threat actors didn’t have to authenticate on the targeted website, the HTTP request made by the attacker will evade all the security checks, and this makes the situation more volatile.

However, the developers of OptinMonster have already invalidated all the API keys that are assumed to be stolen, and they have forced all the website owners to generate the new keys.

Apart from this, all the vulnerable website owners were recommended by the security analysts of the Wordfence Threat Intelligence team to immediately update their old version of OptinMonster with the latest version 2.6.5.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Exploit PHP-CGI RCE Vulnerability to Attack Windows Machines

A recent cybersecurity threat has emerged where unknown attackers are exploiting a critical remote...

Critical DrayTek Router Vulnerabilities Expose Devices to RCE Attacks

A recent security analysis of Draytek Vigor routers has uncovered severe vulnerabilities that could...

Multiple Jenkins Vulnerabilities Allow Attackers to Expose Secrets

Jenkins, the widely-used open-source automation server, issued a high-priority security advisory on March 5,...