CERT-In Vulnerability Note
CIVN-2014-0284
Multiple Vulnerabilities in WordPress plugins
Original Issue Date:December 11, 2014
Severity Rating: HIGH
Systems Affected
- Google Doc Embedder Plugin version before 2.5.15
- Google Analytics by Yoast Plugin version before 5.1.3
- Playlist Free plugin version before 2.7
- SP Client Document Manager plugin version 2.4.1 and earlier
- SupportEzzy Ticket System Plugin version 1.2.5
- Nextend Facebook Connect Plugin version before 1.5.1
- CM Download Manager Plugin version before 2.0.4
Overview
Multiple vulnerabilities have been reported in different plugins of WordPress which could be exploited by a remote attacker to conduct cross-site scripting, SQL injection, HTML injection attacks on the targeted systems.
Description
1. WordPress Google Doc Embedder Plugin SQL Injection Vulnerability
(
CVE-2014-9173
)
This vulnerability exists due to improper sanitization of user-supplied input in view.php file. A remote attacker could exploit this vulnerabilityby sending specially SQL statements, using the "gpid" parameter, to the google-document-embedder\view.php script. Successful exploitation of this vulnerability could allow the attacker to conduct the SQL injection attack and gain access to add, modify or delete the useful data.
2. WordPress Google Analytics by Yoast Plugin Cross Site Scripting Vulnerability
(
CVE-2014-9174
)
This vulnerability exists due to improper sanitization of user-supplied input. A remote attacker could exploit this vulnerability to execute arbitrary web script and HTML in a user's browser session in context of an affected site. Successful exploitation of this vulnerability could allow the attacker to inject malicious JavaScript code and to steal cookie-based authentication credentials.
3. WordPress HTML5 MP3 Player with Playlist Free plugin Information Disclosure Vulnerability
(
CVE-2014-9177
)
A remote attacker could exploit this vulnerability to obtain the installation path whena specially-crafted URL request is made to html5plus/playlist.phpthat cause an error message to be returned containing the full installation path. Successful exploitation of this vulnerability could allow the remote attacker to cause information disclosure vulnerability.
4. WordPress SP Client Document Manager plugin SQL injection Vulnerabilities
(
CVE-2014-9178
)
A remote attacker could exploit this vulnerability to obtain the installation path when a specially-crafted URL request is made to html5plus/playlist.php that cause an error message to be returned containing the full installation path. Successful exploitation of this vulnerability could allow the remote attacker to cause information disclosure vulnerability.
5. WordPress SupportEzzy Ticket System Plugin "URL" Parameter HTML Injection Vulnerability
(
CVE-2014-9179
)
This vulnerability exists due to improper sanitization of user-supplied input. A remote authenticated attacker could exploit this vulnerability to execute arbitrary HTML and script using the "URL (optional)" field in a new ticket in context of an affected site. Successful exploitation of this vulnerability could allow the attacker to gain access of the authentication credentials based on the victim's browser cookies.
6. WordPress Nextend Facebook Connect Plugin Cross Site Scripting Vulnerability
(
CVE-2014-8800
)
This vulnerability exists in the nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1due to improper sanitization of user-supplied input. A remote attacker could exploit this vulnerability using fb_login_button parameter in a newfb_update_options action, to execute arbitrary script code and HTML in the users browser session in context of an affected site. Successful exploitation of this vulnerability could allow the attacker to steal cookie-based authentication credentials and cause unauthorized modification.
7. WordPress CM Download Manager Plugin Remote PHP Code Execution Vulnerability
(
CVE-2014-8877
)
This vulnerability exists due to improper sanitization of user-supplied input. A remote attacker could exploit this vulnerability using CMD search parameter to execute arbitrary PHP code to compromise the affected application.
8. WordPress CM Download Manager Plugin Cross Site Request Forgery Vulnerability
(
CVE-2014-9129
)
This vulnerability exists due to improper sanitization of user-supplied data using "addons_title" POST parameter by the /wp-admin/admin.php script. A remote attacker could exploit this vulnerability by executing arbitrary script code via specially crafted request in user's browser session. Successful exploitation of this vulnerability could allow the remote attacker to conduct cross site scripting attacks.
Solution
Apply appropriate patches as mentioned in the following links
https://wordpress.org/plugins/google-document-embedder/
https://wordpress.org/plugins/google-analytics-for-wordpress/changelog/
https://wordpress.org/plugins/html5-mp3-player-with-playlist/changelog/
https://wordpress.org/plugins/sp-client-document-manager/
https://wordpress.org/news/2014/11/wordpress-4-0-1/
https://wordpress.org/plugins/nextend-facebook-connect/changelog/
https://wordpress.org/plugins/cm-download-manager/
Vendor Information
WordPress
https://wordpress.org
References
WordPress
https://wordpress.org/news/2014/11/wordpress-4-0-1/
SecurityFocus
http://www.securityfocus.com/bid/71330
http://www.securityfocus.com/bid/71267
http://www.securityfocus.com/bid/71237
http://www.securityfocus.com/bid/71433
http://www.securityfocus.com/bid/71204
http://www.securityfocus.com/bid/71418
Xforce
http://xforce.iss.net/xforce/xfdb/99145
http://xforce.iss.net/xforce/xfdb/99053
http://xforce.iss.net/xforce/xfdb/99148
http://xforce.iss.net/xforce/xfdb/99189
CVE Name
CVE-2014-9173
CVE-2014-9174
CVE-2014-9177
CVE-2014-9178
CVE-2014-9179
CVE-2014-9031
CVE-2014-8800
CVE-2014-8877
CVE-2014-9129
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|