Searching
..

Click anywhere to stop

KLA10491
Multiple vulnerabilities in WordPress plugins

Updated: 09/26/2023
Detect date
?
03/17/2015
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in WordPress plugins and themes. Malicious users can exploit these vulnerabilities to execute or inject arbitrary code, bypass security and read local files.

Below is a complete list of vulnerabilities

  1. Multiple XSS vulnerabilities were found in Spider Facebook, Contact Form DB, WooCommerce, WP Media Cleaner, Ninja Forms, WonderPlugin Audio Player, WPML and Google Doc Embedder plugins. By exploiting these vulnerabilities malicious users can inject arbitrary script. These vulnerabilities can be exploited remotely via a unknown vectors related to admin panel;

  2. Multiple CSRF vulnerabilities were found in Mobile Domain, Image Metadata Cruncher, Acobot Live Chat & Contact Form, CrossSlide jQuery, Easy Social Icons and Redirection page plugins. By exploiting these vulnerabilities malicious users can hijack administrators auth. These vulnerabilities can be exploited remotely via an unknown vectors related to admin panel;

  3. Directory traversal vulnerability was found in Elegant Themes Divi theme. By exploiting this vulnerability malicious users can read local files. This vulnerability can be exploited remotely via a specially designed img parameter;

  4. SQL injection vulnerability was found in Apptha WordPress Video Gallery, WonderPlugin Audio Player, Spider Event Calendar, WPML and WordPress Survey and Poll plugins and Photocrati theme. By exploiting this vulnerability malicious users can execute arbitrary SQL commands. This vulnerability can be exploited remotely via a vectors related to admin panel.

  5. Unrestricted file upload was found in Fusion theme. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via an unspecified vectors.

  6. Improper requests handling and other unknown vulnerability were found in WPML plugin. By exploiting this vulnerabilities can bypass security restrictions. These vulnerabilities can be exploited remotely via a specially designed request.
Affected products

Spider Facebook plugin versions earlier than 1.0.11
Mobile Domain plugin version 1.5.2
Redirection Page plugin version 1.2
Elegant Themes Divi theme all versions
Google Doc Embedder plugin versions earlier than 2.5.19
Image Metadata Cruncher plugin all versions
Contact Form DB plugin version 2.8.26
Acobot Live Chat & Contact Form plugin version 2.0
WooCommerce plugin versions earlier than 2.2.11
Apptha WordPress Video Gallery plugin versions earlier than 2.8 
WordPress Survey and Poll plugin version 1.1.7
CrossSlide jQuery plugin version 2.0.5
Easy Social Icons plugin versions earlier than 1.2.3
WonderPlugin Audio Player plugin versions earlier than 2.1
Fusion theme version 3.1
Ninja Forms plugin versions earlier than 2.8.9
Photocrati theme 4 all versions
WPML plugin versions earlier than 3.1.9

Solution

Update to safe version or select another plugin or theme to use

Impacts
?
ACE 
[?]

CI 
[?]

SB 
[?]

RLF 
[?]
Related products
WordPress unclassified products
CVE-IDS
?
CVE-2015-22184.3Warning
CVE-2015-22204.3Warning
CVE-2015-21996.5High
CVE-2015-21967.5Critical
CVE-2015-21954.3Warning
CVE-2015-21946.5High
CVE-2015-23147.5Critical
CVE-2015-23154.3Warning
CVE-2015-20694.3Warning
CVE-2015-15795.0Critical
CVE-2015-15806.8High
CVE-2015-20396.8High
CVE-2015-20404.3Warning
CVE-2015-22167.5Critical
CVE-2015-20896.8High
CVE-2015-20907.5Critical
CVE-2015-20846.8High
CVE-2015-15824.3Warning
CVE-2015-15816.8High
CVE-2015-16146.8High
CVE-2015-27916.4High
CVE-2015-20657.5Critical
CVE-2015-27927.5Critical
CVE-2015-18794.3Warning
Exploitation

Public exploits exist for this vulnerability.

Find out the statistics of the vulnerabilities spreading in your region