Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

This premium WordPress plugin could let hackers hijack your website

  • August 25, 2023
Total
0
Shares
0
0
0


WYSIWYG editor for WordPress and first-draft Elon Musk baby name JupiterX Core has been hijacking accounts and uploading files, but a patch has been issued.

Reporting the news, BleepingComputer also cites Themeforest sales for the JupiterX theme to estimate that it’s used on over 172,000 websites. The real number is probably less than that, but it’s a good indicator of the scale of the problem.

Rafie Muhammad, a researcher at WordPress security firm Patchstack, was the first to discover two distinct vulnerabilities and report them to JupiterX developer ArtBee, who have since patched the flaw. Naturally, if you use this plugin, update your version as soon as possible.

Jupiter X Core WordPress flaw

The first flaw identified, CVE-2023-3838, affects all JupiterX Core versions up to 3.5.5, and allows for file uploads without authentication, opening the floodgates to arbitrary code execution. 

A patch came with version 3.3.8, adding authentication checks into the plugin’s ‘upload_files’ function, as well as a second check to block uploads of, per BleepingComputer, “risky” file types. We imagine this means executables.

The second flaw, CVE-2023-38389, allowed for breaches of any WordPress account so long as any attacker knew the email address attached, impacting up to JupiterX Core version 3.3.8.

 Version 3.4.3 fixed the flaw, with Muhammad writing that the ‘ajax_handler’ function in the plugin’s Facebook login mechanicism let any attacker, for a time, set key login variables involving Facebook user IDs to any value.

ArtBees resolved the issue by pulling a user’s e-mail address and unique user ID from Facebook’s authentication endpoint, though it seems hard to believe that it wasn’t coded that way to begin with.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Orbital Composites lands new government contracts to advance in-space manufacturing

  • August 25, 2023
View Post
Next Article
  • News

Baldur’s Gate 3 PC players have already been playing for 22,000 years combined

  • August 25, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Thursday, September 28 (game #612)

  • September 27, 2023
View Post
  • News

9 things announced at the Meta Connect 2023 event

  • September 27, 2023
View Post
  • News

Sony’s PlayStation Chief to Retire Next Year

  • September 27, 2023
View Post
  • News

Plucky CPU maker beats AMD and Intel to become first to offer 320 cores per server — with even bigger models in the pipeline

  • September 27, 2023
View Post
  • News

Counter-Strike 2 has finally released on PC – players can dive in now

  • September 27, 2023
View Post
  • News

macOS Sonoma has a whole host of security fixes – should we be worried?

  • September 27, 2023
View Post
  • News

The Ray-Ban Stories 2 is here with a new design, new specs, and a new name

  • September 27, 2023
View Post
  • News

The Meta Quest 3 is here, and I think it’s the best VR headset yet

  • September 27, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.