Nasty WordPress plugin bug puts 100,000 sites at risk

scammers
(Image credit: Shutterstock / Brazhyk)

A cross-site scripting (XSS) flaw discovered in the SEOPress WordPress plugin could allow attackers to inject arbitrary web scripts into vulnerable installations and take over websites.

SEOPress is a popular SEO plugin  that's designed specifically for websites that run WordPress and used across roughly 100,000 sites. 

The flaw was discovered by WordPress security experts at Wordfence, who brought it to the attention of the plugin developer last month.

“One feature the plugin implements is the ability to add a SEO title and description to posts, and this can be done while saving edits to a post or via a newly introduced REST-API endpoint. Unfortunately, this REST-API endpoint was insecurely implemented,” wrote Chloe Chamberland, Threat Analyst at Wordfence.

Malicious payloads

Chamberland opines that cross-site scripting vulnerabilities such as the one discovered in SEOPress can be exploited to execute various malicious actions, such as the creation of new administrative accounts, webshell injection, arbitrary redirects, and could even enable an attacker to take over a WordPress website.

Sharing technical details about the vulnerability, Chamberland writes that it could be exploited by any authenticated user, such as a regular subscriber, to update the SEO title and description for any post.

“The payload could include malicious web scripts, like JavaScript, due to a lack of sanitization or escaping on the stored parameters,” says Chamberland, adding that these scripts would execute every time a user accesses the “All Posts” page. 

This flaw has been fully patched in version SEOPress v5.0.4, and Wordfence urges all users of the plugin to update their installations.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Latest in Website Building
Wix automation
The world's leading website builder aims to save businesses time with new tool
Squarespace
Build a website for less with 10% off Squarespace subscriptions
Squarespace
Fresh season, fresh start— launch your dream website with Squarespace with this offer
Wix Printful
Wix teams up with Printful for in-house print-on-demand tools
Squarespace
Don't miss out on this great Squarespace deal
Hostinger Website Builder vs WordPress.com: Which is better?
Hostinger Website Builder vs WordPress.com: Battle of the WordPress website builders
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras