Facebook WordPress plug-ins found to have zero-day flaw

Image credit: Pixabay (Image credit: Image Credit: StockSnap / Pixabay)

Zero-day flaws which impact two of Facebook's official WordPress plugins have been disclosed by a US-based cybersecurity firm including proof-of-concept (PoC) code that could be used by hackers to exploit the flaws and launch attacks against WordPress sites.

The affected plugins include Messenger Customer Chat which shows a custom Messenger chat window on WordPress sites and Facebook for WooCommerce that allows WordPress site owners to upload their WooCommerce-based stores on their Facebook pages.

The Messenger Customer Chat plugin is installed on over 20,000 sites while the Facebook for WooCommerce plugin has 200,000 users after the WordPress team began shipping the plugin as part of the official WooCommerce online store plugin back in April.

Since that time, the plugin has received a rating of 1.5 stars with reviewers complaining about errors and a lack of updates.

Plugin Vulnerabilities vs WordPress

The flaws in these two plugins became much more dangerous when the cybersecurity firm Plugin Vulnerabilities decided to publicly expose them on the WordPress.org forums. 

The firm and WordPress have been feuding for years after a policy change banned users from disclosing security flaws through its forums and instead required security researchers to email the WordPress team who would then contact the owners of any affected plugins.

However, Plugin Vulnerabilities has continued to disclose security flaws on the WordPress forums despite the new rule which resulted in it having its forum accounts banned. The firm took things a step further this spring when it also began to publish blog posts on its site with in-depth details and PoC code about the vulnerabilities it had discovered.

The two zero-day flaws Plugin Vulnerabilities discovered in Facebook's WordPress plugins aren't as dangerous as those it has revealed in the past as they require social engineering to get a user to click on a malicious link. Although the flaws are harder to exploit, they could allow attackers to take over WordPress sites.

Security researchers are generally doing a company a favor when they discover vulnerabilities but by not going through the proper channels to report the vulnerabilities it discovered, the US cybersecurity firm put everyone who has those plugins installed at risk.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
A person holding out their hand with a digital AI symbol.
The decision-maker's playbook: integrating Generative AI for optimal results
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike