Monday, October 7, 2024
HomeWordpressTen WordPress Plugins For WooCommerce Expose E-Commerce Stores to a Range of...

Ten WordPress Plugins For WooCommerce Expose E-Commerce Stores to a Range of Attacks

Published on

Serious security flaws identified in ten WordPress Plugins could be exploited by hackers to upload keyloggers, shells, crypto miners and other malicious software or completely deface the website.

All the plugins are developed by MULTIDOTS Inc to work only with WooCommerce (WordPress eCommerce Platform). The plugins vulnerability puts a number of Store Owners at risk.

Researchers from threatpress identified the ten WordPress Plugins and reported to MULTIDOTS Inc, but the vendor failed to patch the plugins.

So it has been reported by threatpress o the WordPress plugin repository security team and the plugins are taken down from the store on May 23, 2018. According to the WordPress plugin repository, over 19,400 active installs of these ten Vulnerable WordPress Plugins.
- Advertisement - EHA

As there is too many up’s and down’s in WordPress usage, it requires a security consideration, so the WordPress Penetration testing is essential to find the vulnerabilities and to secure your WordPress powered blog.

Ten WordPress Plugins

WooCommerce Category Banner Management – Unauthenticated Settings Change
Add Social Share Messenger Buttons Whatsapp and Viber – Cross-site Request Forgery
Advanced Search for WooCommerce – Stored Cross-site scripting (XSS)
Eu Cookie Notice – Cross-site request forgery (CSRF)
Mass Pages/Posts Creator – Authenticated Stored Cross-Site Scripting (XSS)
Page Visit Counter – SQL Injection
WooCommerce Checkout For Digital Goods – Cross-site request forgery (CSRF)
WooCommerce Enhanced E-commerce Analytics Integration with Conversion Tracking – Cross-site request forgery (CSRF) and Stored Cross-site scripting (XSS)
WooCommerce Product Attachment – Authenticated stored Cross-site scripting (XSS)
Woo Quick Reports – Stored Cross-Site Scripting (XSS)

ten Vulnerable WordPress Plugins

“The author (MULTIDOTS Inc.) failed to fix the problem within a period of 3 weeks. It’s good to know that WordPress Security reacts quickly, but still, we have a big problem.” Threatpress published blog PoC for all the vulnerabilities.

These vulnerabilities tracked as CVE-2018-11579, CVE-2018-11580, CVE-2018-11633 and CVE-2018-11632 and still, the vulnerabilities are not patched.

“We hope to see some changes in this area. In this case, we could notify owners of affected websites and secure almost twenty thousand websites.”

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hybrid Analysis Utilizes Criminal IP’s Robust Domain Data for Better Malware Detection

Criminal IP, a renowned Cyber Threat Intelligence (CTI) search engine developed by AI SPERA,...

RCE Vulnerability (CVE-2024-30052) Allow Attackers To Exploit Visual Studio via Dump Files

The researcher investigated the potential security risks associated with debugging dump files in Visual...

Cacti Network Monitoring Tool Vulnerability Let Attackers Execute Remote Code

A critical security vulnerability has been identified in the Cacti network monitoring tool that...

Microsoft & DOJ Dismantles Hundreds of Websites Used by Russian Hackers

Microsoft and the U.S. Department of Justice (DOJ) have disrupted the operations of Star...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Unauthenticated RCE in WordPress Plugin Exposes 100,000 WordPress Sites

A critical vulnerability has been discovered in the GiveWP plugin, a popular WordPress donation...

Hackers Actively Exploiting WordPress Plugin Arbitrary File Upload Vulnerability

Hackers have been actively exploiting a critical vulnerability in the WordPress plugin 简数采集器 (Keydatas)....

SocGholish Malware Attacking Windows Users Using Fake Browser Update

The SocGholish downloader has been in operation since 2017 and it is still evolving....