Best Website-BuildersBest Website-Builders
    What's Hot

    Swansea: Gas explosion destroys homes in major incident

    March 13, 2023

    Insulate Britain protester jailed for stopping traffic on M4

    March 13, 2023

    BBC boss denies climbdown over Lineker impartiality row

    March 13, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website-BuildersBest Website-Builders
    • Home
    • CSS

      Almost Bare Bone WebR Starter App

      March 12, 2023

      Best AI Tools for Web Designers (2023)

      March 12, 2023

      PSPad 5.0.7.770 | Neowin

      March 11, 2023

      Battle of Memphis

      March 11, 2023

      How to create a recipe book using HTML, CSS and JavaScript

      March 11, 2023
    • Joomla

      Mufti Menk – How can it be better for me?

      March 13, 2023

      Pros, Cons, & Pricing Compared

      March 11, 2023

      Give your website a place to call home for a lifetime of web hosting for just $100

      March 11, 2023

      Give your website a place to call home for a lifetime of web hosting for just $100

      March 11, 2023

      12 Best Free Web Hosting Sites to Choose From

      March 10, 2023
    • PHP

      Lawsuit says teacher pushed student for not saying pledge of allegiance

      March 12, 2023

      Paul Flores sentenced to 25 years for murder of Christine Smart

      March 12, 2023

      Most Effective Skin Serum, According to Reviewers and Dermatologists

      March 12, 2023

      Man sues ex-wife’s friend for helping ex-wife get abortion

      March 11, 2023

      Perfect indoor and outdoor slippers to wear around the house or on errands

      March 11, 2023
    • UX

      New Lexus RZ major on refinement and fresh thinking

      March 13, 2023

      Lexus RZ Review (2023) | Auto Car

      March 13, 2023

      Evolution of Tourism UI/UX Design: Trends to Watch

      March 13, 2023

      Introducing Qi and how to make wireless charging more pervasive

      March 13, 2023

      Which Product Designer Specialization is the most expensive?

      March 13, 2023
    • Web Builders
      1. Web Design
      2. View All

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      Can Religious Freedom Be Saved? This group is racing the clock to teach America’s first freedom

      February 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023

      Is There A Market For Rap-Themed Slot Games? – Rap Review

      January 19, 2023
    • WordPress

      Microsoft says most UK companies fail to recognize technology’s potential

      March 13, 2023

      No wonder Sonos wants to make a wireless soundbar.

      March 13, 2023

      iPhone 14 series cases probably won’t fit most iPhone 15 models.

      March 13, 2023

      Quordle today – Tips and Answers for Monday March 13th (Game #413)

      March 13, 2023

      A big Samsung Galaxy S23 camera update is rumored to be in the works

      March 12, 2023
    • Realtoz
      • Our Other Sites
    • More News
    Best Website-BuildersBest Website-Builders
    Home » Shortcode Ultimate WordPress Vulnerability Affects 700,000 Sites
    Wordpress

    Shortcode Ultimate WordPress Vulnerability Affects 700,000 Sites

    websitebuildersnowBy websitebuildersnowOctober 12, 2022No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The US government’s National Vulnerability Database (NVD) released an advisory on the Shortcodes Ultimate WordPress plugin, warning that it was found to contain a cross-site request forgery vulnerability.

    Shortcodes Ultimate is a very popular WordPress plugin with over 700,000 active installs.

    This vulnerability affects plugin versions older than the current version 5.12.2.

    Cross-site request forgery vulnerability

    Cross-site request forgery, commonly referred to as CSRF, is a type of vulnerability that, in the worst case scenario, can lead to complete website takeover.

    This kind of vulnerability is usually caused by targeting software flaws that can cause changes, which can lead to unintended consequences.

    Successful attacks typically depend on whether the user has administrative privileges or clicks a link to unintentionally reveal information such as a session cookie that can be used to impersonate that person.

    This type of vulnerability relies on social engineering to manipulate the end-user to complete an action that exploits the plugin’s vulnerability.

    According to the Open Web Application Security Project (OWASP):

    “CSRF is an attack that tricks the victim into submitting a malicious request.

    Inherit the victim’s identity and privileges to perform unwanted functions on the victim’s behalf…

    For most sites, browser requests automatically include credentials associated with the site, such as the user’s session cookie, IP address, and Windows domain credentials.

    Therefore, if the user is currently authenticated to the site, the site has no way of distinguishing between bogus requests submitted by the victim and legitimate requests submitted by the victim. “

    National Vulnerability Database (NVD)

    The National Vulnerability Database has released just a few details about the vulnerability. There is currently no full breakdown of the vulnerabilities themselves.

    The following information has been published in the NVD advisory:

    “Cross-site request forgery (CSRF) vulnerability in WordPress Shortcodes Ultimate plugin <= 5.12.0 modifies plugin preset settings."

    The official Shortcodes Ultimate GitHub changelog is similarly vague, describing updates to fix vulnerabilities.

    “### 5.12.1

    **Security Release**

    This update fixes a security vulnerability in the shortcode generator. Thanks to Dave John for discovering it. “

    On the other hand, the changelog in the WordPress plugin repository explains:

    “Fixed issue with shortcode generator presets introduced in last update”

    The changelog above appears to misspell the name of the security researcher, but the person who discovered and reported the vulnerability, Dave Jong, CTO of Patchstack, has it spelled correctly.

    Recommended course of action

    WordPress publishers currently using the shortcode plugin should consider updating to the latest version. This is currently version 5.12.2 at the time of writing.

    Quote

    Read the National Vulnerability Database Advisory

    CVE-2022-38086 Details

    Read the patch stack announcement

    WordPress Shortcodes Ultimate Plugin <= 5.12.0 – Cross-Site Request Forgery (CSRF) Vulnerability

    Featured image from Shutterstock/Cookie Studio





    Source link

    Share this:

    • Tweet
    • Email
    • Pocket
    • Mastodon
    • WhatsApp
    • Telegram
    • Share on Tumblr
    • Print
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleLack of security in hidden DNS resolvers leaves website hijacking risk pervasive
    Next Article Bridging the UX and build environment
    websitebuildersnow
    • Website

    Related Posts

    Microsoft says most UK companies fail to recognize technology’s potential

    March 13, 2023

    No wonder Sonos wants to make a wireless soundbar.

    March 13, 2023

    iPhone 14 series cases probably won’t fit most iPhone 15 models.

    March 13, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Swansea: Gas explosion destroys homes in major incident

    March 13, 2023

    Insulate Britain protester jailed for stopping traffic on M4

    March 13, 2023

    BBC boss denies climbdown over Lineker impartiality row

    March 13, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.