Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
BID:48405
Info
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
| Bugtraq ID: | 48405 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2011 12:00AM |
| Updated: | Jun 23 2011 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
WordPress W3 Total Cache 0.9.2.3 WordPress Plugin 1.9.28 WordPress AddThis 2.2 |
| Not Vulnerable: |
WordPress WPtouch 1.9.29 |
Discussion
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
Multiple WordPress plugins are prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer.
The following plugins are affected:
AddThis
W3 Total Cache
WPTouch
Multiple WordPress plugins are prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application. Successful attacks will compromise the affected application and possibly the webserver or computer.
The following plugins are affected:
AddThis
W3 Total Cache
WPTouch
Exploit / POC
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Multiple WordPress Plugins Compromised Source Packages Backdoor Vulnerability
References:
References:
- Passwords Reset News (WordPress)
- WordPress Homepage (WordPress)