CERT-In Vulnerability Note
CIVN-2014-0290
Multiple Vulnerabilities in various plugins for WordPress
Original Issue Date:December 31, 2014
Severity Rating: MEDIUM
Systems Affected
- WordPress Download Manager plugin versions prior to 2.6.92
- WordPress W3 Total Cache plugin version prior to 0.9.4.1
Overview
Multiple vulnerabilities have been reported in various WordPress plugins which could be exploited by remote attackers to bypass certain security restrictions or conduct attacks like Cross Site Scripting.
Description
1. Authorization Security Bypass Vulnerability in WordPress Download Manager Plugin
This vulnerability exists in the plugin as it fails to restrict the access to certain administrative functionality. A remote attacker could exploit this vulnerability to bypass security restrictions by executing arbitrary PHP code.
2. Cross Site Scripting Vulnerability in Wordpress W3 Total Cache plugin
(
CVE-2014-8724
)
The vulnerability occurs when the option "Page cache debug info" is enabled which results in the addition of HTML-Comments. A remote attacker could leverage this issue to conduct cross-site scripting by injecting arbitrary web script or HTML via the "Cache key".
Solution
Apply appropriate updates as mentioned in WordPress Security Advisory
https://wordpress.org/plugins/w3-total-cache/changelog/
https://wordpress.org/plugins/download-manager/changelog/
Vendor Information
WordPress
https://wordpress.org/plugins/download-manager/changelog/
https://wordpress.org/plugins/w3-total-cache/changelog/
References
Security Focus
http://www.securityfocus.com/archive/1/archive/1/534266/100/0/threaded
WordPress
https://wordpress.org/plugins/download-manager/changelog/
https://wordpress.org/plugins/w3-total-cache/changelog/
XForce
http://xforce.iss.net/xforce/xfdb/95919
CVE Name
CVE-2014-8724
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|