Moneycontrol PRO
HomeNewsTechnologyWordPress Download Manager plugin patches security flaw

WordPress Download Manager plugin patches security flaw

The plugin was weak to a remote code execution flaw that would have allowed hackers to upload and run malicious files

July 31, 2021 / 13:18 IST
The remote code execution vulnerability has now been fixed

The remote code execution vulnerability has now been fixed

A security flaw in a popular WordPress plugin called WordPress Download Manager has now been fixed. The flaw allowed hackers to run and upload malicious files on the websites that ran the plugin.

According to the security researchers at Wordfence, the plugin has been installed on more than 100,000 websites that use WordPress and was found weak to two severe flaws. The first one allowed was a file upload vulnerability that would have let threat actors remotely execute malicious code and the second was a vulnerability to a double extension attack through which a file with multiple extensions could be used to trigger code.

As explained by Wordfence, "a user with author-level permissions could also upload a file with an image extension containing malicious JavaScript and set the contents of file[page_template] to the path of the uploaded file."

This would have allowed the actor to take control of the site by obtaining credentials or by remotely executing a code in the administrator's browser session.

The second vulnerability allowed authors and other users to perform a double extension attack. For instance, "it was possible to upload a file titled info.php.png. This file would be executable on certain Apache/mod_php configurations that use an AddHandler or AddType directive."

Both of the vulnerabilities have been fixed by the plugin's developer.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Jul 31, 2021 01:18 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347