Buggy WordPress Plugin Allows Users to Wipe Whole Websites

Security researchers with Wordfence - a security-focused plugin for WordPress - found a critical bug in another plugin for the publishing platform. The issue was spotted in the HashThemes Demo Importer addon for WordPress and the severity of the issue is quite high.

The fault in the HashThemes Demo Importer plugin allowed a user who has logged into the WordPress platform and has access to a website's backend to completely wipe all content, including pages, articles and media, as well as the contents of databases used by the site. According to statistics, some 8 thousand websites had the plugin active when the bug was discovered.

The original purpose of the demo importer plugin is to let WordPress-based site admins import demos of WordPress visual themes and designs with a single click. The plugin significantly speeds up the previewing process and does not involve manual handling of different setting files that may be specific to the site and theme used.

The team over at Wordfence disclosed the bug following due protocol but the demo importer developer did not respond for weeks on end. Finally, the researchers brought the issue directly to the WordPress plugins team and the faulty version of the plugin was taken down on the same day. Four days later, a patched and fixed version was put back up.

Wordfence explained that the issue with the plugin lay in the way it was using Ajax. The bug allowed any user who was logged in, even those with very limited default rights and access such as subscribers, to make drastic changes to the website, including completely wiping out all content on the site running the plugin.

The simple takeaway here is that every convenient plugin that you might want to add to your existing WordPress setup increases the potential surface for attack. Richer functionality and greater ease of use don't always have to come at the expense of security, but with third-party plugins, there is always the possibility that a few cracks are present and hidden in plain sight.

October 28, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.