Another top WordPress plugin found carrying critical security flaws

WordPress
(Image credit: Pixabay)

  • Researchers from Patchstack find two new flaws in Fancy Product Designer
  • The Radykal-built WordPress plugin has more than 20,000 active users
  • The flaws allowed for remote code execution, arbitrary file upload, and more

A popular WordPress plugin was found carrying two critical vulnerabilities that allow threat actors to upload files, tamper with databases, and essentially take over compromised websites.

To make matters worse, the vulnerabilities remained in the code for more than half a year, despite the developers being notified, and actively working on new versions in the meantime.

Cybersecurity researchers from Patchstack claim in late March 2024, they discovered two vulnerabilities in Fancy Product Designer, a premium website builder plugin developed by Radykal, which allows users to create and customize products, such as t-shirts, mugs, or posters, with various design tools and options for e-commerce stores. It has more than 20,000 sales.

Silence of the vendors

The vulnerabilities are tracked as CVE-2024-51919 (severity score 9.0), and CVE-2024-51818. The former is an unauthenticated arbitrary file upload vulnerability, while the latter is an unauthenticated SQL injection flaw. Since the former allows for remote code execution (RCE), it could lead to full website takeover in some scenarios.

Patchstack claims to have notified the vendor of the issues in late March, but never heard back from the company. In the meantime, Radykal was working on new versions of the plugin, and released 20 of them. The latest one was pushed two months ago (6.4.3), and it still carries the critical security flaws.

To warn users of the risks, and to draw attention to the problem, Patchstack added the bugs to its database, and published an in-depth blog, with the technical information found within enough to build an exploit and target websites using Fancy Product Designer.

To prevent that from happening, web admins should create a whitelist of allowed file extensions, and thus stop threat actors from uploading whatever they please. Patchstack added that users should sanitize user input for a query to defend against SQL injection attacks, too.

Via BleepingComputer

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another major WordPress plugin has been hacked to try and hijack your sites
WordPress
Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games