WordPress Plugin Vulnerabilities

Multiple WP-Buy Plugins - Arbitrary Plugin Installation/Activation via CSRF

Description

The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical vulnerabilities like RCE.

Proof of Concept

Affects Plugins

Classification

Miscellaneous

Original Researcher
WPScanTeam
Verified
Yes

Timeline

Publicly Published
2021-04-22 (about 4 years ago)
Added
2021-04-22 (about 4 years ago)
Last Updated
2021-04-22 (about 4 years ago)

Other