{"id":1488,"date":"2024-07-17T08:26:45","date_gmt":"2024-07-17T08:26:45","guid":{"rendered":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/07\/17\/millions-of-wordpress-sites-vulnerable-to-compromise-due-to-plugin-bug-sc-media\/"},"modified":"2024-07-17T08:26:45","modified_gmt":"2024-07-17T08:26:45","slug":"millions-of-wordpress-sites-vulnerable-to-compromise-due-to-plugin-bug-sc-media","status":"publish","type":"post","link":"https:\/\/www.yellowfalconmedia.com\/blog\/2024\/07\/17\/millions-of-wordpress-sites-vulnerable-to-compromise-due-to-plugin-bug-sc-media\/","title":{"rendered":"Millions of WordPress sites vulnerable to compromise due to plugin bug &#8211; SC Media"},"content":{"rendered":"<p>More than five million WordPress sites could be compromised due to an unauthenticated site-wide cross-site scripting flaw in the LiteSpeed Cache&nbsp;<a href=\"https:\/\/www.scmagazine.com\/news\/wordpress-plugin-under-attack-bricks-builder-bug-enables-rce\" target=\"_blank\" id=\"\" rel=\"noreferrer noopener\">plugin<\/a>, tracked as CVE-2023-40000, which could be exploited to facilitate privilege escalation attacks, according to&nbsp;<a href=\"https:\/\/thehackernews.com\/2024\/02\/wordpress-litespeed-plugin.html\" target=\"_blank\" id=\"\" rel=\"noreferrer noopener\">The Hacker News<\/a>.<br \/>Inadequate user input sanitization and escaping output have caused the vulnerability, which has been addressed in an October update but could be abused through a single HTTP request, a report from Patchstack showed. &#8220;Since the XSS payload is placed as an admin notice and the admin notice could be displayed on any wp-admin endpoint, this vulnerability also could be easily triggered by any user that has access to the wp-admin area,&#8221; said Patchstack researcher Rafie Muhammad. Such a vulnerability is the second XSS bug impacting the LiteSpeed Cache plugin after CVE-2023-4372 was reported by Wordfence researchers in August. Exploiting CVE-2023-4372 &#8220;makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page,&#8221; noted Wordfence researcher Istvan Marton.<br \/><span itemscope=\"\" itemtype=\"https:\/\/schema.org\/Person\" itemprop=\"author\" class=\"me-2\"><a itemprop=\"url\" rel=\"author\" href=\"\/contributor\/karl-mattson\"><span itemprop=\"name\"><span itemprop=\"givenName\">Karl <!-- --> <\/span><span itemprop=\"familyName\">Mattson <\/span><\/span><\/a><\/span><time class=\"non-interactive\" datetime=\"2024-06-03T07:00:00.000-04:00\">June 3, 2024<\/time><br \/>Here are three ways to build APIs that deliver the functionality and security modern organizations need. <br \/><span itemscope=\"\" itemtype=\"https:\/\/schema.org\/Person\" itemprop=\"author\" class=\"me-2\"><a itemprop=\"url\" rel=\"author\" href=\"\/contributor\/steve-zurier\"><span itemprop=\"name\"><span itemprop=\"givenName\">Steve<!-- --> <\/span><span itemprop=\"familyName\">Zurier<\/span><\/span><\/a><\/span><time class=\"non-interactive\" datetime=\"2024-05-31T15:16:00.000-04:00\">May 31, 2024<\/time><br \/>Fastly says the bugs are prone to unauthenticated XXS attacks that let threat actors inject malicious scrips via WordPress plug-ins.<br \/><span itemscope=\"\" itemtype=\"https:\/\/schema.org\/Person\" itemprop=\"author\" class=\"me-2\"><a itemprop=\"url\" rel=\"author\" href=\"\/contributor\/laura-french\"><span itemprop=\"name\"><span itemprop=\"givenName\">Laura<!-- --> <\/span><span itemprop=\"familyName\">French<\/span><\/span><\/a><\/span><time class=\"non-interactive\" datetime=\"2024-05-16T18:50:00.000-04:00\">May 16, 2024<\/time><br \/>GenAI, API and identity risks are key concerns, as well as conflicts between DevOps and SecOps.<\/p>\n<p>By clicking the Subscribe button below, you agree to SC Media <a class=\"text-underline\" target=\"_blank\" href=\"https:\/\/www.cyberriskalliance.com\/terms-of-use\" rel=\"noopener\">Terms and Conditions<\/a><span> and <\/span><a class=\"text-underline\" target=\"_blank\" href=\"https:\/\/www.cyberriskalliance.com\/terms-of-use#privacy-policy\" rel=\"noopener\">Privacy Policy<\/a>.<\/p>\n<p>         Copyright \u00a9 2024 CyberRisk Alliance, LLC All Rights Reserved.         This material may not be published, broadcast, rewritten or redistributed         in any form without prior authorization.       <br \/><span>Your use of this website constitutes acceptance of CyberRisk Alliance <\/span><a class=\"text-underline cursor-pointer\" target=\"_blank\" href=\"https:\/\/www.cyberriskalliance.com\/terms-of-use#privacy-policy\" rel=\"noopener\">Privacy Policy<\/a><span> and <\/span><a class=\"text-underline cursor-pointer\" target=\"_blank\" href=\"https:\/\/www.cyberriskalliance.com\/terms-of-use\" rel=\"noopener\">Terms of Use<\/a><span>.<\/span><\/p>\n<p><a href=\"https:\/\/news.google.com\/rss\/articles\/CBMiZ2h0dHBzOi8vd3d3LnNjbWFnYXppbmUuY29tL2JyaWVmL21pbGxpb25zLW9mLXdvcmRwcmVzcy1zaXRlcy12dWxuZXJhYmxlLXRvLWNvbXByb21pc2UtZHVlLXRvLXBsdWdpbi1idWfSAQA?oc=5\">source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than five million WordPress sites could be compromised due to an unauthenticated site-wide cross-site scripting flaw in the LiteSpeed Cache&nbsp;plugin, tracked as CVE-2023-40000, which could be exploited to facilitate privilege escalation attacks, according to&nbsp;The Hacker News.Inadequate user input sanitization and escaping output have caused the vulnerability, which has been&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1488","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/1488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/comments?post=1488"}],"version-history":[{"count":0,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/posts\/1488\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/media?parent=1488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/categories?post=1488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yellowfalconmedia.com\/blog\/wp-json\/wp\/v2\/tags?post=1488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}