High-severity WordPress plugin bug puts thousands of websites at risk

scammers
(Image credit: Shutterstock / Brazhyk)

Researchers have disclosed a severe security vulnerability affecting a WordPress plugin installed across more than 20,000 websites.

According to a blog post from security firm Wordfence, the bug is present in older versions of the Access Demo Importer plugin, which lets WordPress users import demo content, widgets, theme options and other settings to their sites.

If exploited, the vulnerability could reportedly allow attackers with subscriber-level access to upload arbitrary files that set the stage for remote code execution. Wordfence says that sites with open registration could be particularly vulnerable to this exploit.

The vulnerability has been assigned a severity score of 8.8/10 as per the Common Vulnerability Scoring System (CVSS).

WordPress plugin vulnerability

The Access Demo Importer vulnerability is said to originate in a feature that allows users to install plugins hosted outside of the official WordPress repository.

“Unfortunately, this function had no capability check, nor any nonce checks, which made it possible for authenticated users with minimal permissions, like subscribers,  to install a zip file as a ‘plugin’ from an external source,” explained Wordfence.

“This ‘plugin’ zip file could contain malicious PHP files, including webshells, that could be used to achieve remote code execution and ultimately completely take over a site.”

The vulnerability was first identified by Wordfence in early August. After a series of failed attempts to get in contact with the vendor, the security firm escalated the issue to the WordPress.org team and the plugin was pulled down to allow the developers to put together a patch. A partial fix was rolled out in early September, followed by a comprehensive patch on September 21.

To shield against attack, WordPress users are advised to update to the latest version of the Access Demo Importer plugin (version 1.0.7) immediately.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
WordPress
Another top WordPress plugin found carrying critical security flaws
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)