This entry was posted in Research, Vulnerabilities, WordPress Security on February 16, 2021 by Chloe Chamberland 0 Replies
On January 20, 2021, our Threat Intelligence team responsibly disclosed four vulnerabilities in Ninja Forms, a WordPress plugin used by over one million sites. One of these flaws made it possible for attackers to redirect site administrators to arbitrary locations. The second flaw made it possible for attackers with subscriber level access or above to …
Read More
This entry was posted in Research, Vulnerabilities, WordPress Security on February 10, 2021 by Chloe Chamberland 4 Replies
On December 17, 2020, our Threat Intelligence team responsibly disclosed three vulnerabilities in Responsive Menu, a WordPress plugin installed on over 100,000 sites. The first flaw made it possible for authenticated attackers with low-level permissions to upload arbitrary files and ultimately achieve remote code execution. The remaining two flaws made it possible for attackers to …
Read More
This entry was posted in Research, Vulnerabilities, WordPress Security on February 08, 2021 by Ram Gall 4 Replies
On December 14, 2020, the Wordfence Threat Intelligence team finished researching two Cross-Site Request Forgery (CSRF) vulnerabilities in NextGen Gallery, a WordPress plugin with over 800,000 installations, including a critical severity vulnerability that could lead to Remote Code Execution(RCE) and Stored Cross-Site Scripting(XSS). Exploitation of these vulnerabilities could lead to a site takeover, malicious redirects, …
Read More
This entry was posted in Research, WordPress Security on February 04, 2021 by Chloe Chamberland 9 Replies
On December 9, 2020, the Wordfence Threat Intelligence team discovered a Cross-Site Request Forgery (CSRF) to Stored Cross Site Scripting (XSS) vulnerability in Contact Form 7 Style, a WordPress plugin installed on over 50,000 sites. Please note that this is a separate plugin from “Contact Form 7” and is designed as an add-on to that …
Read More
This entry was posted in Research, Wordfence, WordPress Security on February 02, 2021 by Gregory Bloom 1 Reply
Wordfence is the leader in WordPress security, protecting over 4 million WordPress sites from malicious attacks. With new malware variants discovered daily, we now have a new weapon in our arsenal against WordPress attacks: Machine Learning. How Wordfence identifies malware For years, the Wordfence Threat Intelligence team has stayed ahead of attackers by quickly identifying …
Read More
This entry was posted in General Security, Research, Wordfence, WordPress Security on January 27, 2021 by Ram Gall 4 Replies
Over the course of 2020, and in the process of protecting over 4 million WordPress customers, the Wordfence Threat Intelligence team gathered a massive amount of raw data from attacks targeting WordPress and infection trends, in addition to the malware samples gathered by our Site Cleaning team. Attacks on WordPress can be categorized in three …
Read More
This entry was posted in Vulnerabilities, WordPress Security on January 18, 2021 by Ram Gall 11 Replies
Update: The Proof of Concept posted on exploit-db has been removed since the publication of this article. We have updated the link to point to an archived copy. On December 17, 2020, the Astra research security team disclosed that they had discovered a critical severity Unrestricted File Upload vulnerability in Contact Form 7, the most …
Read More
This entry was posted in Research, Vulnerabilities, WordPress Security on January 12, 2021 by Chloe Chamberland 1 Reply
On November 19, 2020, our Threat Intelligence team responsibly disclosed two vulnerabilities in Orbit Fox by ThemeIsle, a WordPress plugin used by over 400,000 sites. One of these flaws made it possible for attackers with contributor level access or above to escalate their privileges to those of an administrator and potentially take over a WordPress …
Read More
This entry was posted in General Security, Research, WordPress Security on December 24, 2020 by Chloe Chamberland 18 Replies
Chloe Chamberland is a threat analyst and member of the Wordfence Threat Intelligence Team. She holds the following certifications: OSCP, OSWP, OSWE, Security+, CySA+, PenTest+, CASP+, SSCP, Associate of (ISC)2, CEH, ECSA and eWPT. Many of these are advanced certifications including OSCP and OSWE which are 24 and 48 hour exams respectively, that require hands-on …
Read More
This entry was posted in General Security, WordPress Security on December 23, 2020 by Ram Gall 2 Replies
The SolarWinds supply chain attack is all over the news, impacting government agencies, telecommunications firms, and other large organizations. The security firm FireEye was the first victim of the attack, disclosing that they had been hacked on December 8, 2020. On December 13th the US Treasury Department announced that it had also been compromised. At …
Read More