WordPress found few vulnerabilities: Know how to fix them


Team Udayavani, Aug 1, 2021, 12:32 PM IST

Two vulnerabilities have been found in the WordPress plugin that was installed on over 1,00,000 websites. WordPress Download Manager, the plugin is used to change how download pages are displayed.

The Wordfence Threat Intelligence team found the vulnerabilities.

WordPress Download Manager has some protections in place to protect against directory traversal, they did not prove to be sufficient in this particular case, leading to a contributor with lower privileges being able to retrieve the contents of a site’s wp-config.php file by adding a new download and performing a directory traversal attack.

The contents of the wp-config.php were visible in the page’s source code upon previewing the download and as the contents of the file were echoed out onto the page source, a user with author-level access could also upload a file or multimedia containing malicious JavaScript and set the contents of the file to the path of the uploaded file which could result in Stores Cross-Site Scripting.

Earlier, the WordPress Download Manager team had patched a vulnerability that allowed users to upload files with php4 extensions as well as other potentially malicious files. But reports stated that this patch protected many configurations, it only checked the last file extension that made it possible for an attacker to carry out a “double extension” attack by uploading a file with multiple extensions like info.php.png.

Website owners who use WordPress are advised to update to the latest version immediately as the WordPress team and developers have released a patch.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

India Nets: Shami works on lengths with Morkel, Pant recovers after freak hit by Hardik shot

To ban or not to ban? Countries debate regulations on smartphone usage in schools

PM didn’t tell his good friend about country’s outrage over handcuffing Indian deportees: Congress

Maha Kumbh: Akhilesh seeks compensation to kin of devotees killed in accidents

K’taka irrigation issues: CM urges Deve Gowda to come forward to protect state’s interest

Two held in Rs 850 crore ponzi scheme case: Cyberabad Police

Delhi stampede: Opposition blames govt for ‘gross mismanagement’, demands Vaishnaw’s resignation

Related Articles More

Is AI making us stupider? Maybe, according to one of the world’s biggest AI companies

ISRO develops 10-tonne propellant mixer for solid motors

Military gadgets that can be used by civilians jostle for space at Aero India 2025

Hubballi startup develops AI-powered ‘Chakra’ net trap to neutralize enemy drones

HAL’s Hindustan Jet Trainer HJT-36 is now renamed as ‘Yashas’

MUST WATCH

25 years old chat shop in Katapadi

Ashok Kumar Rai

Brahma Baidarkala Nemaotsava

Tea & Tales: A 10,000-Book Library Inside a Tea Shop!

Sri Goshala Bangalore

Latest Additions

India Nets: Shami works on lengths with Morkel, Pant recovers after freak hit by Hardik shot

To ban or not to ban? Countries debate regulations on smartphone usage in schools

PM didn’t tell his good friend about country’s outrage over handcuffing Indian deportees: Congress

Maha Kumbh: Akhilesh seeks compensation to kin of devotees killed in accidents

“Namma Sante” buzz: From coconut shell art to pure honey delights!

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.