Security News > 2020 > January > Critical WordPress Bug Leaves 320,000 Sites Open to Attack

Critical WordPress Bug Leaves 320,000 Sites Open to Attack
2020-01-15 21:19

Two WordPress plugins, InfiniteWP Client and WP Time Capsule, suffer from the same critical authorization bypass bug that allows adversaries to access a site's backend with no password.

All an attacker needs is the admin username for the WordPress plugins and they are in, according to researchers from WebArx who created proof-of-concept attacks to exploit the vulnerability.

According to the WordPress plugin library, 300,000 websites are running a version of the vulnerable InfiniteWP Client plugin.

Both plugins are designed to allow users to authenticate to multiple WordPress installations from one central server.

That allows site owners to "Perform maintenance such as one-click updates for core, plugins, and themes across all sites, backup and site restores, and activating/deactivating plugins and themes on multiple sites simultaneously," according to a WordFence description.


News URL

https://threatpost.com/wordpress-bug-leaves-sites-open-to-attack/151911/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159