Menu
WordPress e-commerce plug-in puts over 5,000 websites at risk

WordPress e-commerce plug-in puts over 5,000 websites at risk

Unpatched flaws could allow attackers to take control of websites running a WordPress plug-in called TheCartPress

TheCartPress, an e-commerce plug-in used on thousands of WordPress-based websites, has several high-risk vulnerabilities.

There are currently no fixes available for the flaws and, according to its developer, support for the plug-in will be discontinued on June 1st.

The vulnerabilities could allow attackers to "execute arbitrary PHP code, disclose sensitive data, and perform Cross-Site Scripting [XSS] attacks against users of WordPress installations with the vulnerable plug-in," researchers from security firm High-Tech Bridge said in an advisory Wednesday.

There are factors that limit the exploitation of some of the flaws, but they still pose a significant risk.

For example, exploiting the vulnerability that allows PHP code execution requires the attacker to have administrative privileges on the WordPress website. However, an attacker could also trick the real administrator into running the exploit by visiting a malicious page, according to the High-Tech Bridge researchers. This is known as a cross-site request forgery (CSRF) attack.

Another vulnerability allows unauthenticated attackers to browse orders placed by users of the e-commerce site that uses the plug-in.

There are also multiple XSS issues, both in the administrative panel and user-accessible pages. These flaws could allow attackers to trick the site's users into performing rogue actions when they click on specifically crafted URLs. XSS attacks where the victim is the site's administrator obviously carry the highest risk.

The High-Tech Bridge researchers claim that they tried to notify the plug-in's developer about the flaws since Apr. 8 without success. They point out that the developer has already announced that "support for TheCartPress will end on June 1, 2015."

Since it's not clear if the flaws will ever be fixed, the researchers recommend disabling or removing the plug-in. According to statistics from the official WordPress plug-in repository, TheCartPress currently has over 5,000 active installations.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags intrusionsecurityHigh-Tech BridgeExploits / vulnerabilities

Slideshows

Meet the leading HP partners in New Zealand...

Meet the leading HP partners in New Zealand...

HP has recognised its top performing partners in New Zealand at the second annual 2016 HP Partner Awards, held at a glittering bash in Auckland. The HP Partner Awards recognises and celebrates excellence, growth, consistency and engagement of its top partners. This year also saw the addition of several new categories, resulting in 11 companies winning across 11 award categories.

Meet the leading HP partners in New Zealand...
Channel comes together as Ingram Micro Showcase hits Auckland

Channel comes together as Ingram Micro Showcase hits Auckland

Ingram Micro outlined its core focuses for 2017 at Showcase in Auckland, bringing together the channel for a day of engaging keynotes, compelling breakout sessions and new technologies.

Channel comes together as Ingram Micro Showcase hits Auckland
Show Comments