Tampa Tech Wire - News and Technology From Around The Bay                  

Multiple Vulnerabilities Patched in Shield Security WordPress Plugin

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp
Shield Security WordPress Vulnerability

April 25, 2023Ram Gall – On March 20, 2023, the Wordfence Threat Intelligence team began the responsible disclosure process for two vulnerabilities in Shield Security, a security plugin with over 50,000 installations. One of these vulnerabilities allowed unauthenticated attackers to inject malicious JavaScript into an administrator dashboard in some configurations, while another allowed authenticated attackers to spoof log entries into the same dashboard, which could also be used to exploit the first vulnerability in configurations where the unauthenticated technique was not viable.

We received a response and sent over full disclosure, and a patched version, 17.0.18, was released the same day.

Wordfence PremiumCare, and Response users received a firewall rule to protect against any exploits targeting this vulnerability on March 20, 2023. Sites still using the free version of Wordfence received the same protection on April 19, 2023.


Description: Shield Security <= 17.0.17 – Unauthenticated Stored Cross-Site Scripting
Affected Plugin: Shield Security – Smart Bot Blocking & Intrusion Prevention
Plugin Slug: wp-simple-firewall
Affected Versions: <= 17.0.17
CVE ID:CVE-2023-0992
CVSS Score: 7.2 (High)
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Researcher/s: Ramuel Gall
Fully Patched Version: 17.0.18

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the ‘User-Agent’ header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


Description: Shield Security <= 17.0.17 – Missing Authorization
Affected Plugin: Shield Security – Smart Bot Blocking & Intrusion Prevention
Plugin Slug: wp-simple-firewall
Affected Versions: <= 17.0.17
CVE ID:CVE-2023-0993
CVSS Score: 4.3 (Medium)
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Researcher/s: Ramuel Gall
Fully Patched Version: 17.0.18

The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the ‘theme-plugin-file’ AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edited, and is also a vector for Cross-Site Scripting via CVE-2023-0992.


Vulnerability Analysis

The Shield Security plugin includes a number of features, including an audit log that records certain types of suspicious activity, such as plugin and theme installation, modification, post deletion, and other types of activity that might impact the site. While most of these events require authentication or higher privileges in order to trigger, we found that certain events could be triggered by unauthenticated users. In particular, failed attempts to authenticate using application passwords, new user registrations, and spam activity are among the actions recorded for unauthenticated users.

The audit log records metadata about the client that performed the logged activity, including the client’s User-Agent, which can be accessed by clicking the “Meta” tag icon on an audit log entry. Unfortunately, the metadata was not escaped when it was output. While most of the metadata collected about a request has a very strict format and can only be spoofed to a limited extent, User-Agent strings are alphanumeric, and we were able to inject a script in an iframe in the User-Agent header that fired when an administrator viewed an event entry:

While this exploit does technically require user interaction, it can be considered “Passive” user interaction, that is, it does not require tricking the administrator into performing any actions they might not have performed otherwise. Depending on the payload used, an attacker could use the script executing in the administrator’s browser to create a new administrator account under their control. Additionally, this exploit can be automated, and can be exploited by unauthenticated attackers via a variety of vectors, at least one of which is likely to be present in most common site configurations. As such it earns its High severity rating.

The second vulnerability was much lower in severity and consisted of a missing authorization check on the ‘edit-theme-plugin-file’ AJAX action, which is used to record edits to plugin or theme files. The primary consequence of this is that an authenticated attacker can spoof an audit log entry indicating that any file belonging to any plugin or theme on the site was edited. While this is primarily a nuisance, since it can be used to create audit log entries it is yet another vector to exploit the aforementioned Cross-Site Scripting vulnerability.

Disclosure Timeline

March 20, 2023 – Wordfence PremiumCare, and Response users receive a firewall rule to provide protection against any exploits that may target this vulnerability. We responsibly disclose the plugin to the developer, who responds quickly and releases a patch in version 17.0.18.
April 19, 2023 – The firewall rule becomes available to all Wordfence users.

Conclusion

In today’s post, we detailed a High Severity Cross-Site Scripting vulnerability in Shield Security. We also detailed a lower-severity issue allowing authenticated attackers to spoof audit log entries indicating that plugin and theme files had been edited. These vulnerabilities have been fully patched in version 17.0.18.

Wordfence PremiumCare, and Response users received a firewall rule to protect against any exploits targeting this vulnerability on March 20, 2023. Sites still using the free version of Wordfence received the same protection on April 19, 2023.

Latest IT Security

WordPress Privileged Escalation

Privilege Escalation Vulnerability Patched Promptly in WP Data Access WordPress Plugin

April 13, 2023

On April 5, 2023 the Wordfence Threat Intelligence team initiated the responsible...

WordPress

WordPress force patching WooCommerce plugin with 500K installs

March 24, 2023

Automattic, the company behind the WordPress content management system, is force installing...

GoDaddy Hacked - Again! | Tampa Tech Wire - News and Tech from Around the bay

GoDaddy finds hackers running amok – Nearly 3 years & 3 hacks later

February 20, 2023

The web host says it fell victim to a two-year security breach...

How to Protect Your Apple ID With Security Keys | Tampa Tech Wire - News and Technology from Around The Bay

How to Protect Your Apple ID With Security Keys

February 15, 2023

The entire Apple ecosystem is built around Apple ID, so you need...

If you know a friend or colleague who is using the Shield Security plugin on their site, we highly recommend forwarding this advisory to them as the Cross-Site Scripting vulnerability can allow Unauthenticated attackers to execute malicious JavaScript in an administrator’s browser, which can lead to site takeover.

If you are a security researcher, you can responsibly disclose your finds to us and obtain a CVE ID and get your name on the Wordfence Intelligence leaderboard. Thanks to Paul Goodchild from Shield Security for patching the issue quickly.

Facebook
Twitter
LinkedIn
Pinterest
Pocket
WhatsApp
Your subscription could not be saved. Please try again.
Thanks for subscribing!

Newsletter

Never miss any important news. Subscribe to our newsletter.

Your subscription could not be saved. Please try again.
Thanks for subscribing!

Newsletter

Never miss any important news. Subscribe to our newsletter.

Recent News

Popular

Blog Subscriber Form