Menu
WordPress e-commerce plug-in puts over 5,000 websites at risk

WordPress e-commerce plug-in puts over 5,000 websites at risk

Unpatched flaws could allow attackers to take control of websites running a WordPress plug-in called TheCartPress

TheCartPress, an e-commerce plug-in used on thousands of WordPress-based websites, has several high-risk vulnerabilities.

There are currently no fixes available for the flaws and, according to its developer, support for the plug-in will be discontinued on June 1st.

The vulnerabilities could allow attackers to "execute arbitrary PHP code, disclose sensitive data, and perform Cross-Site Scripting [XSS] attacks against users of WordPress installations with the vulnerable plug-in," researchers from security firm High-Tech Bridge said in an advisory Wednesday.

There are factors that limit the exploitation of some of the flaws, but they still pose a significant risk.

For example, exploiting the vulnerability that allows PHP code execution requires the attacker to have administrative privileges on the WordPress website. However, an attacker could also trick the real administrator into running the exploit by visiting a malicious page, according to the High-Tech Bridge researchers. This is known as a cross-site request forgery (CSRF) attack.

Another vulnerability allows unauthenticated attackers to browse orders placed by users of the e-commerce site that uses the plug-in.

There are also multiple XSS issues, both in the administrative panel and user-accessible pages. These flaws could allow attackers to trick the site's users into performing rogue actions when they click on specifically crafted URLs. XSS attacks where the victim is the site's administrator obviously carry the highest risk.

The High-Tech Bridge researchers claim that they tried to notify the plug-in's developer about the flaws since Apr. 8 without success. They point out that the developer has already announced that "support for TheCartPress will end on June 1, 2015."

Since it's not clear if the flaws will ever be fixed, the researchers recommend disabling or removing the plug-in. According to statistics from the official WordPress plug-in repository, TheCartPress currently has over 5,000 active installations.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securityintrusionExploits / vulnerabilitiesHigh-Tech Bridge

Featured

Slideshows

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Kiwi channel debates GDPR as Reseller News Exchange hits Wellington

Kiwi channel debates GDPR as Reseller News Exchange hits Wellington

This exclusive Reseller News Exchange, in association with Arrow ECS ANZ, ForeScout and StorageCraft, went on the road to debate the early implications of GDPR in New Zealand, extracting opportunities while evaluating challenges for the channel in the year ahead.

Kiwi channel debates GDPR as Reseller News Exchange hits Wellington
Show Comments