Patch the Facebook for WordPress plugin now, users warned

Person editing a WordPress site
(Image credit: Pixabay)

The Threat Intelligence team at Wordfence has discovered two vulnerabilities in Facebook's WordPress plugin that if left unpatched, could be exploited by an attacker to achieve remote code execution or to inject malicious JavaScript into the plugin's settings.

Facebook for WordPress is a plugin designed to create a seamless integration between the conversion measurement tool Facebook Pixel and a WordPress site. Once installed, the plugin monitors site traffic and records data when users access pages and perform certain actions on a site.

The first flaw discovered by Wordfence could be used by unauthenticated attackers with access to a site's secret salts and keys to achieve remote code execution through a deserialization weakness. The company responsibly disclosed the vulnerability to Facebook at the end of last year and it has now been patched.

Facebook for WordPress

The second flaw discovered in Facebook for WordPress by Wordfence's Threat Intelligence team was introduced when the plugin was rebrandred with the launch of version 3.0.0. 

If exploited, this flaw could allow for attackers to inject malicious JavaScript into the plugin's settings if an attacker could successfully trick a WordPress admin into performing an action such as clicking on a link. Wordfence reached out to Facebook's security team at the end of January of this year to inform them about the second vulnerability.

Both vulnerabilities in Facebook for WordPress should be patched immediately as the PHP Object Injection vulnerability has a CVSS score of 9.0 and is rated as critical while the Cross-Site Request Forgery has a CVSS Score of 8.8 and is rated as high.

Version 3.0.5 of the Facebook for WordPress plugin is available now and the latest version of the plugin contains patches that address both vulnerabilities.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
WordPress
Another top WordPress plugin found carrying critical security flaws
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost