Unrestricted Access FEB 2022
Tailored WordPress Security Report
Be informed about the latest Unrestricted Access FEB 2022 - WP Security Circumvention, identified and reported publicly. These breaches create even more problems and vulnerability exploitation with a severe negative impact on any WordPress Security. Consider our security consulting.
An jaw-dropping estimated 4.536.000+ active WordPress installations are susceptible to these attack types, considering only the publicly available numbers. It is a mind-boggling 69% increase compared to last month. The estimated number can double with premium versions as they are private purchases.
Furthermore, the initial estimation can multiply if we consider the already patched versions BUT NOT UPDATED by owners, as the vulnerability remains active within their domain. As these owners start changing their hosting provider (due to constant unexplained issues), they actively migrate these vulnerabilities behind protected areas, possibly exposing other clean WP to different attack types.
The following cases made headlines PUBLICLY in the Unrestricted Access FEB 2022 category:
Hire security professionals to protect your WordPress from publicly reported cases of Unrestricted Access FEB 2022 BEFORE IT’S TOO LATE! You will also protect your customers, your reputation and your online business!
- Nitro | Best Premium WooCommerce Theme For Your Online Shop - Unauthenticated Arbitrary Plugin Installation
- The only WooCommerce Theme with customer conversion mindset: eCommerce features, 3s page load speed and 18+ designs with home, product, landing sales pages. Active installations: N/A
- Download
WebP Converter for Media – Convert WebP and AVIF & Optimize Images - Unauthenticated Open redirect- Speed up your website by serving WebP and AVIF images. By replacing files in standard JPEG, PNG and GIF formats with WebP and AVIF formats, you can save over a half of the page weight without losing quality. Active installations: 100,000+
- Link Library - Reflected Cross-Site Scripting (XSS)
- Link Library - Library Settings Reset via Cross-Site Request Forgery (CSRF)
- Link Library - Unauthenticated Arbitrary Links Deletion
- This plugin is used to be able to create a page on your web site that will contain a list of all of the link categories that you have defined inside of the Links section of the WordPress administration, along with all links defined in these categories. The user can select a sub-set of categories to be displayed or not displayed. Link Library also offers a mode where only one category is shown at a time, using AJAX or HTML Get queries to load other categories based on user input. It can display a search box and find results based on queries. It can also display a form to accept user submissions and allow the site administrator to moderate them before listing the new entries. Finally, it can generate an RSS feed for your link collection so that people can be aware of additions to your link library. Active installations: 10,000+
- Axact Author List Widget - Unauthenticated SQL Injection
- The Axact Author List Widget wordpress plugin, by Yumna Tatheer, displays a list of authors, and editors on the blog as an ordered list, unordered list, or a dropdown list. You can use the ordered list to display a list of ‘top authors’ on the blog. You can set a custom order of authors by simple dran n drop, set urls where this widget should not show. Active installations: 200+
- Perfect Survey - Unauthorised AJAX Call to Stored Cross-Site Scripting (XSS) / Survey Settings Update
- Perfect Survey - Unauthenticated SQL Injection
- Perfect Survey - Reflected Cross-Site Scripting (XSS)
- Perfect Survey - Unauthenticated Stored Cross-Site Scripting (XSS)
- This plugin has been closed as of October 5, 2021 and is not available for download. Reason: Security Issue.
- Paid Memberships Pro – WordPress Membership Plugin - Unauthenticated Blind SQL Injection
- Paid Memberships Pro gives you all the tools you need to start, manage, and grow your membership site. The plugin is designed for premium content sites, online course or LMS and training-based memberships, clubs and associations, members-only product discount sites, subscription box products, paid newsletters, and more. Active installations: 100,000+
- NextScripts: Social Networks Auto-Poster - Arbitrary Post Deletion via Cross-Site Request Forgery (CSRF)
- NextScripts: Social Networks Auto-Poster - Unauthenticated Stored Cross-Site Scripting (XSS)
- This plugin automatically publishes posts from your blog to your Social Media accounts such as Facebook, Twitter, Google+(Google Plus), Blogger, Tumblr, Flickr, LinkedIn, ok.ru, LiveJournal, DreamWidth, Flipboard, Instagram, Telegram, Line, Diigo, Instapaper, Pinterest, Plurk, VK.com (VKontakte), YouTube, Scoop.It, WordPress, XING etc. Active installations: 90,000+
- Contact Form Entries – Contact Form 7, WPforms and more - Unauthenticated Stored Cross-Site Scripting (XSS)
- Contact Form 7 Entries Plugin automatically saves form submissions from Contact Form 7, WPforms, CRM Perks Forms and many other popular contact form plugins to wordpress database when anyone submits a form. Active installations: 40,000+
- SupportCandy – Helpdesk & Support Ticket System - Stored Cross-Site Scripting (XSS)
- SupportCandy – Helpdesk & Support Ticket System - Cross-Site Request Forgery (CSRF) to Cross-Site Scripting (XSS)
- SupportCandy – Helpdesk & Support Ticket System - Arbitrary Ticket Deletion via Cross-Site Request Forgery (CSRF)
- SupportCandy – Helpdesk & Support Ticket System - Unauthenticated Arbitrary Ticket Deletion
- SupportCandy – Helpdesk & Support Ticket System - Reflected Cross-Site Scripting (XSS)
- This plugin adds to WordPress the features of a complete helpdesk ticket system. Easy to configure and easy to use is our first priority. Active installations: 10,000++
- Document Embedder - Arbitrary Private/Draft Post Title Disclosure
- Document Embedder - Unauthenticated Arbitrary Private/Draft Post Title Disclosure
- Embed any documents such as Word, Excel, PowerPoint, Apple Pages, Psd, Pdf +more 10 Type of document in your wordpress website. Very easy to use, user friendly & lite weight plugin. Active installations: 9,000+
- Woopra Analytics Plugin - Unauthenticated Arbitrary File Upload
- Woopra is an end-to-end Customer Journey Analytics solution built for teams. Unify your customer data within the platform to analyze, optimize and engage across every customer touchpoint. Active installations: 2,000+
- True Ranker - Unauthenticated Arbitrary File Access via Path Traversal
- Now you can enjoy for free with the only SEO App that gives you total control of your geolocated Google results with 100% real accuracy. With TRUE RANKER we offer real and accurate information about the rankings of your keywords depending on the country, state or city from which the search is made. Active installations: 300+
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes - Unauthenticated Arbitrary CSS Update
- CMP – Coming Soon & Maintenance plugin has all premium features you ever wished for, and it is free! It is also super fast and user friendly. You can activate your Maintenance, Coming soon(under construction) or a Landing page with a single click. Customizable in many ways – you can select a layout from predefined Themes, set custom logo, background graphics (including YouTube videos or Unsplash images), custom text or graphic content, subscribe form, social networks icons, change typography, colors, SEO, and many more. Active installations: 100,000+
- WP Import Export Lite - Unauthenticated Sensitive Data Disclosure
- WordPress Import Export gives you ability to export you site data into Multiple file format and you can import those file in any of your site. All type of your Posts, Pages, Custom Post Types, Taxonomies, Comments and Users import/export in just one click. A great way to manage WordPress Site data between multiple sites. Active installations: 20,000+
- Popup | Custom Popup Builder - Unauthenticated Denial of Service
- Popup Plugin can create high converting popups with notification message or subscriber forms. Within few seconds popup will be live on your site after installtion of this popup plugin. Active installations: 1,000+
- Form Store to DB - Unauthenticated Stored Cross-Site Scripting (XSS)
- Form Store To DB is a FREE plugin for WordPress that you can use as extension for storing entries submitted via the contact form 7 without losing all the data including the attachments. Entries from the contact form 7 plugin will be stored safely even if the form failed to get submitted or any of your email get lost, deleted or removed by mistake. Active installations: 80+
- WP Import Export PREMIUM - Unauthenticated Sensitive Data Disclosure
- WP Import Export Plugin is an easy, quick and advanced Import & Export site data. WP Import Export gives you ability to export you site data into Multiple file format and you can import those file in any of your site. All type of your Posts, Pages, Custom Post Types, Taxonomies, Comments and Users import/export in just one click. A great way to manage WordPress Site data between multiple sites. Active installations: N/A
- GiveWP – Donation Plugin and Fundraising Platform - Unauthenticated Reflected Cross-Site Scripting (XSS)
- GiveWP – Donation Plugin and Fundraising Platform - Reflected Cross-Site Scripting (XSS)
- GiveWP is the highest rated, most downloaded, and best supported donation plugin for WordPress. Whether you need a simple donate button or a powerful donation platform optimized for online giving, GiveWP is right for you. Active installations: 100,000+
- WP Post Page Clone - Unauthorised Post Access
- WP Post Page Clone is a WordPress plugin that allows you to easily duplicate or clone post/page in just one click. Active installations: 80,000+
- IP2Location Country Blocker - Arbitrary Country Ban via Cross-Site Request Forgery (CSRF)
- IP2Location Country Blocker - Arbitrary Country Ban
- IP2Location Country Blocker - Ban Bypass
- This plugin enables user to block unwanted traffic from accesing your frontend (blog pages) or backend (admin area) by countries or proxy servers. It helps to reduce spam and unwanted sign ups easily by preventing unwanted visitors from browsing a particular page or entire website. Active installations: 10,000+
- User Rights Access Manager - Access Restriction Bypass
- User Rights Access Manager is a lightweight and powerful plugin that grants you complete control on your admin area’s content by restricting access of admin menus, submenus, post-types to specific user or specific user roles. Active installations: 900+
- UpdraftPlus WordPress Backup Plugin - Local File Inclusion
- UpdraftPlus WordPress Backup Plugin - Reflected Cross-Site Scripting (XSS)
- UpdraftPlus WordPress Backup Plugin - Stored Cross-Site Scripting (XSS)
- WP-Appbox - Authenticated Local File Inclusion
- With WP-Appbox you can add beautiful mobile app badges to your WordPress posts and pages simply by adding a shortcode. WP-Appbox supports the following app stores: Active installations: 6,000+
- Easy Drag And drop All Import : WP Ultimate CSV Importer - Arbitrary Option Deletion
- Easy Drag And drop All Import : WP Ultimate CSV Importer - Arbitrary File Upload
- Import your unlimited data into WordPress as CSV, XML, txt or zip file using WP Ultimate CSV importer. Import your content on WordPress using this best CSV importer quick and simple with a few steps. Built-in drag and drop facility is also available to make the import process a hassle-free task in less time. No other special requirements are needed to import any CSV or XML files. Active installations: 10,000+
- Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages - Arbitrary Settings Update to Stored Cross-Site Scripting (XSS)
- Generate a professional Privacy Policy, terms of use, terms & conditions, eCommerce returns & refunds policy, affiliate disclaimers & more. Covers 25+ expert vetted legal pages for WordPress websites. Active installations: 20,000+
- Ultimate Product Catalog - Arbitrary Product Creation & Settings Update
- Product catalog plugin that is responsive and designed to display your products in a sleek and easy to customize catalog format. Active installations: 3,000+
- TrustMate.io – integracja z WooCommerce - Arbitrary Plugin’s Settings Update
- TrustMate.io – integracja z WooCommerce - Arbitrary Blog Option Update
- TrustMate – Reviews for your shop and products at you WooCommerce site. Generate valuable traffic and profit more than others! Active installations: 400+
- Side Cart Woocommerce (Ajax) - Cross-Site Request Forgery (CSRF) to Arbitrary Options Update
- Say good bye to your woocommerce cart page. With side cart users can access cart items from anywhere on your site. Active installations: 60,000+
- PHP Everywhere - Arbitrary Settings Update via Cross-Site Request Forgery (CSRF)
- This plugin enables PHP code everywhere in your WordPress instalation. Active installations: 30,000+
- PPOM for WooCommerce - Settings Update to Stored Cross-Site Scripting (XSS)
- WooCommerce PPOM (Personalized Product Option Manager) Plugin adds input fields on product page to personalized your product. Drag & Drop input fields with many options. Prices can also be added with options. All data will be attached with order and email. Active installations: 20,000+
- Login/Signup Popup ( Inline Form + Woocommerce ) - Cross-Site Request Forgery (CSRF) to Arbitrary Options Update
- A simple and lightweight plugin which makes registration, login & reset password process super smooth. You get two awesome fully customizable designs – Popup & Inline form with shortcodes. You can choose which field to keep from the fields manager. Active installations: 20,000+
- Ibtana – WordPress Website Builder - Settings Update to Stored Cross-Site Scripting (XSS)
- Ibtana Gutenberg Editor has ready made eye catching responsive templates build with custom blocks and options to extend Gutenberg’s default capabilities. You can easily import demo content for the block or templates with a single click. Once done, you can straight away start making the desired changes. It also kit with individual components and blocks to build internal pages. Now you don’t need to invest too much time in editing or recreating the template you love. Now its just drag and drop and easy edit of your favourite template with just few clicks. Active installations: 10,000+
- Waitlist Woocommerce ( Back in stock notifier ) - Cross-Site Request Forgery (CSRF) to Arbitrary Options Update
- Waitlist for woocommerce lets you track demand for out-of-stock items, ensuring your customers feel informed, and therefore more likely to buy. Active installations: 4,000+
- Duplicate Page or Post - Arbitrary Settings Update to Stored Cross-Site Scripting (XSS)
- WordPress Duplicate Page or Post plugin is an nice and useful tool if you need to copy your pages or posts. Active installations: 10,000+
- Five Star Business Profile and Schema - page creation and settings update leading to Stored Cross-Site Scripting (XSS)
- Add schema structured data to any page and/or post type on your site. Also easily create a contact card to add all your business details with the correct structured data. Enhance your site with SEO friendly Schema.org markup. Active installations: 10,000+
- Catch Web Tools - Arbitrary Catch IDs Activation/Deactivation
- Catch Web Tools is a modular plugin that powers up your WordPress site with simple and utilitarian features. It currently offers Webmaster Tool, Open Graph, Custom CSS, Social Icons, Security, Updator and Basic SEO optimization modules with more addition in updates to come. Active installations: 20,000+
- Lean WP - Arbitrary Plugin Activation
- This plugin has been closed as of March 31, 2020 and is not available for download. This closure is permanent. Reason: Author Request.
- AF Companion - Arbitrary Plugin Installation & Activation via Cross-Site Request Forgery (CSRF)
- Import live demo content, widgets, and settings swiftly. This plugin gives fundamental layout to build your website & accelerate the development process. Active installations: 9,000+
- Classic Editor Addon - Arbitrary Plugin Installation from Dependency via Cross-Site Request Forgery (CSRF)
- Classic Editor Addon - Arbitrary Plugin Activation
- The free Classic Editor Addon plugin is targeted at everyone who is not yet ready for the new editing experience that has been introduced in WordPress 5.0. Install it now on sites and the UX remains the same as you are used to! Active installations: 30,000+
- Ultimate FAQ – WordPress FAQ and Accordion Plugin - Arbitrary FAQ Creation
- FAQ plugin for WordPress. With this plugin you can easily create FAQs and add them to your WordPress site using a Gutenberg block or shortcode. It makes use of a custom post type for seamless FAQ integration on any site. Active installations: 40,000+
- LabTools - Arbitrary Publication Deletion
- This plugin has been closed as of December 28, 2021 and is not available for download. This closure is temporary, pending a full review.
- Error Log Viewer by BestWebSoft - Arbitrary Text File Deletion via Cross-Site Request Forgery (CSRF)
- This plugin has been closed as of November 10, 2021 and is not available for download. Reason: Security Issue.
- Advanced Cron Manager – debug & control - Arbitrary Events/Schedules Creation/Deletion
- With Advanced Cron Manager you can manage WP Cron events and schedules. Active installations: 30,000+
- RVM – Responsive Vector Maps - Arbitrary File Read
- Create responsive linkable vector maps in one click, many customizations possible, toggle elements on the page or display content over the maps. All settings in one page! Active installations: 6,000+
- Advanced Cron Manager PRO - Arbitrary Events/Schedules Creation/Deletion
- With Advanced Cron Manager PRO you will get premium Cron logger! Investigate Cron executions with no hassle! Active installations: N/A
- Futurio Extra - User Email Address Leakage
- Futurio Extra brings new widgets to be used in Elementor and allows you to import beautiful page templates for Elementor page builder. It also comes with 100% WooCommerce support and custom options. Active installations: 30,000+
- Popup Builder – Create highly converting, mobile friendly marketing popups. - LFI to RCE
- Popup Builder – Create highly converting, mobile friendly marketing popups. - SQL Injection
- Popup Builder is a Perfect solution for any WordPress website. With a wide range of WordPress popup types, conditions, and events (From Image Popup to Countdown popup, Exit Intent to GeoTargeting) Popup Builder helps you create high converting, promotional and informative popups, increase conversion rates and boost sales while reaching your marketing goals. Active installations: 200,000+
- WordPress Email Template Designer – WP HTML Mail - Unprotected REST-API Endpoint
- Custom designed WordPress emails for your WooCommerce and EDD transactional emails, contact form notifications, your WordPress core emails, BuddyPress and many more. Active installations: 20,000+
- AnyComment - Comment Rating Increase/Decrease via Race Condition
- AnyComment - Arbitrary HyperComments Import/Revert via Cross-Site Request Forgery (CSRF)
- AnyComment is blazing-fast commenting plugin base on React for WordPress. Active installations: 4,000+
Get Healthy, Stay Healthy! A healthier online business starts today and it begins with you. Hire security experts to solve all your vulnerabilities created from Unrestricted Access FEB 2022.
BRIEF: Open and Unrestricted Access FEB 2022 to anything within a website is one thing everybody considers to be a total disaster. Many employees have come to rely on the Internet both for work and day-to-day life. As such, they demand unrestricted access at work, and many company bosses have obliged. Without the knowledge to them, however, there may be a risk associated with this.
What is Unauthenticated Insecure Deserialisation?
Insecure Deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application, inflict a denial of service (DoS) attack, or even execute arbitrary code upon it being deserialized. If the function that is responsible for converting serial data into a structured object assumes that the data is trusted, an attacker may format the serial data in such a way that the result of deserialization is malicious. Unfortunately, many standard deserialization functions in programming languages assume that the data is safe.
What is Unauthenticated Backup Download?
The plugin does not restrict access to a BACKUP file containing sensitive information, such as the internal path of backups, which may then allow unauthenticated users to download them.
What is Unrestricted File Upload?
By exploiting this vulnerability, attackers could simply upload files of any type, bypassing all restrictions placed regarding the allowed upload-able file types on a website. By doing this, it allows an attacker to inject malicious content such as web shells into the sites, and providing a method for initial access into the system.
What is Login Rate Limiting Bypass?
When the plugin is configured with a custom header in its Trusted IP Origins setting (e.g X-Forwarded-For), attackers could bypass the protection offered by tampering the header sent in requests. When the plugin is configured to accept an arbitrary header as client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does never reach the maximum allowed retries.
What is Improper Authorisation Check?
An attacker could leverage these issues to dump the database including administrative user credentials, to steal cookie-based authentication credentials, or launch other attacks. An anonymous user may create a new dive entry with a crafted HTTP POST.
SOLVE TODAY any reported Unrestricted Access FEB 2022 vulnerability! Do you suspect any security circumvention in your WordPress?