Saturday, January 18, 2025
HomeInternetCritical Vulnerability in Wordpress Ad Inserter Plugin Let Hackers to Execute Arbitrary...

Critical Vulnerability in WordPress Ad Inserter Plugin Let Hackers to Execute Arbitrary PHP Code

Published on

SIEM as a Service

Follow Us on Google News

A critical remote code execution vulnerability in WordPress plugin Ad Inserter, let hackers execute arbitrary PHP code in the vulnerable installations.

The vulnerability was discovered by Wordfence security team and the vulnerability can be executed only by the authenticated users starting from Subscribers to above user levels.

The Ad Inserter used on over 200,000 websites and the functionality of the plugin to insert different kind of ads, opt-in forms and other scripts on the WordPress websites.

This issue is categorized as a critical one and has CVSS Score 9.9, the websites running Ad Inserter 2.4.21 or below are affected.

Wordfence reported the vulnerability to the plugin developer and the patch was released in the next day itself, users are recommended to update with 2.4.22 right away.

With this plugin, an ad preview feature option available which let’s website administrators to see how their ad appears on the web page.

This action can be done only by the website by authenticated users and also the plugin has check_admin_referer(), which ensures the action to be done by site administrator only.

But the vulnerability discovered by Wordfence shows that security control in place: check_admin_referer() is not enough and the nonce has been compromised to get the appropriate privileges.

The Ad Inserter also includes that includes troubleshooting features, which includes a Javascript on every page, according to “Wordfence the Javascript contains a valid nonce for the ai_ajax_backend action and the debugging feature can be triggered by any user who has this special cookie.”

By having the nonce string in hand, an attacker with Subscriber or above user account can exploit the vulnerability in ad preview feature by executing malicious PHP code, explains Wordfence.

By using tools such as WPScan you can scan the WordPress sites for vulnerabilities.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Hackers Easily Bypass Active Directory Group Policy to Allow Vulnerable NTLMv1 Auth Protocol

Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured...

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

PoC Exploit Released for Ivanti Connect Secure RCE Vulnerability

A serious security flaw has been identified in Ivanti Connect Secure, designated as CVE-2025-0282, which...