WordPress found few vulnerabilities: Know how to fix them


Team Udayavani, Aug 1, 2021, 12:32 PM IST

Two vulnerabilities have been found in the WordPress plugin that was installed on over 1,00,000 websites. WordPress Download Manager, the plugin is used to change how download pages are displayed.

The Wordfence Threat Intelligence team found the vulnerabilities.

WordPress Download Manager has some protections in place to protect against directory traversal, they did not prove to be sufficient in this particular case, leading to a contributor with lower privileges being able to retrieve the contents of a site’s wp-config.php file by adding a new download and performing a directory traversal attack.

The contents of the wp-config.php were visible in the page’s source code upon previewing the download and as the contents of the file were echoed out onto the page source, a user with author-level access could also upload a file or multimedia containing malicious JavaScript and set the contents of the file to the path of the uploaded file which could result in Stores Cross-Site Scripting.

Earlier, the WordPress Download Manager team had patched a vulnerability that allowed users to upload files with php4 extensions as well as other potentially malicious files. But reports stated that this patch protected many configurations, it only checked the last file extension that made it possible for an attacker to carry out a “double extension” attack by uploading a file with multiple extensions like info.php.png.

Website owners who use WordPress are advised to update to the latest version immediately as the WordPress team and developers have released a patch.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Maharashtra Polls: Eknath Shinde targets Uddhav for `giving up’ Bal Thackeray’s principles for power

Will appear before Lokayukta for questioning in MUDA case, says CM Siddaramaiah

Lies have short life, Cong’s ‘fake’ narrative smashed: Fadnavis

Temple idols found desecrated in Hyderabad, case registered

SC junks plea against quashing of LOC issued to ex-house help of Sushant Singh Rajput

JPC chairman Jagdambika Pal to visit K’taka on Nov 7 to meet farmers protesting Waqf notices

Indian boxer Mandeep Jangra wins WBF’s world title

Related Articles More

Stay Safe Online: Tips to avoid cyber fraud!

Three Chinese astronauts enter space station after successful launch

What is AI superintelligence? Could it destroy humanity? And is it really almost here?

IIT-B develops method to maintain comfortable temperature inside homes in joint research

Scammers use fear and urgency to con people using ‘digital arrest’, online scams: Cyber advisory

MUST WATCH

Gho Pooja in Deepavali Festival

Melukote Deepavali

Ganapathi Co-operative Society Ltd

Udayavani Chinnara Banna 2024

Annapoorna Aahar | Food Places In Mysore


Latest Additions

Davanagere: Man murdered by relative for insurance money; 4 arrested within 24 hours

Heroin worth Rs 3.5 crore recovered in police raid in Delhi, 2 arrested

Govt clerk found dead in Tahsildar’s chamber, FIR filed against minister’s PA, 2 others

Treated Muslims like fuel for ‘lantern’: Prashant Kishor targets Lalu, asks upper castes to stay away from Nitish

MP Brijesh Chowta urges Kerala CM for strict action against attack on Edneer Swamiji’s vehicle

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.