ZeroHour
Security Affairspublished ()ingested @securityaffairs

Flaws in Social Warfare plugin actively exploited in the wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-9978

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-9978
Stored XSS in WordPress Social Warfare Plugin (CVE-2019-9978) Exploited in the Wild

CVE-2019-9978 is a stored cross-site scripting (CWE-79) flaw in the Social Warfare social-sharing plugin for WordPress: the plugin's debug routine at wp-admin/admin-post.php?swp_debug=load_options accepts an unauthenticated swp_url parameter and uses it to pull in attacker-controlled settings/content that is then persisted on the site. An attacker triggers the flaw by simply sending an unauthenticated request to admin-post.php with swp_debug=load_options and a crafted swp_url; the injected content later executes in the browsers of WordPress administrators when they view the affected dashboard or pages. Successful exploitation lets an attacker run arbitrary JavaScript in admin sessions, change plugin and site settings, and inject malicious scripts, redirects, or content into the site; public PoCs and the in-the-wild exploits were described as escalating to remote code execution. Any WordPress site running Social Warfare or Social Warfare Pro before version 3.5.3 is affected. The flaw was exploited as a zero-day in March 2019, is on CISA's KEV (added 2021-11-03) with a 72.9% EPSS (99th percentile), and related reporting indicates widespread active exploitation with follow-on web shell activity.

Do: Upgrade Social Warfare and Social Warfare Pro to version 3.5.3 or later immediately (apply updates per vendor instructions) and verify the installed version under Plugins in wp-admin. If updating is not possible right away, deactivate the plugin or block unauthenticated requests to admin-post.php that include the swp_debug parameter. Review plugin settings, posts, and pages for injected JavaScript, check administrator accounts for additions or changes, and hunt for web shells given reported follow-on deployments.

6.173% KEV PoC ×5
  • warfareplugins Social Warfare (WordPress plugin) before 3.5.3
  • warfareplugins Social Warfare Pro (WordPress plugin) before 3.5.3
largeroughly tens of thousands of sites (≈60,000–70,000 WordPress installs at the time of the March 2019 disclosure)
Full article461 words · extracted from securityaffairs.com · click to collapse

Experts uncovered hacking campaigns exploiting two critical security vulnerabilities in the popular WordPress plugin Social Warfare.

Social Warfare is a popular ùWordPress plugin with more than 900,000 downloads, it allows to add social share buttons to a WordPress website.

Experts uncovered hacking campaigns exploiting two critical security vulnerabilities in the Social Warfare plugin to take control over WordPress websites using it.

At the end of March, experts found a Cross-Site Scripting (XSS) vulnerability in Social Warfare installations (v3.5.1 and v3.5.2) that is actively exploited to add malicious redirects.

Maintainers of Social Warfare for WordPress also addressed a remote code execution (RCE), both issues were tracked as CVE-2019-9978.

The issue in the WordPress plugin has been fixed with the release of the 3.5.3 version of the plugin. In the same day, an unnamed security researcher published technical details of the flaw and a proof-of-concept exploit for the stored Cross-Site Scripting (XSS) vulnerability.

Experts pointed out that attackers can exploit the vulnerabilities to take complete control over websites and servers and use them for malicious purposed, such as mining cryptocurrency or deliver malware.

The availability of the exploit code allowed attackers attempting to exploit the vulnerability, but hackers were only able to inject JavaScript code to redirect users to malicious sites.

Experts at Palo Alto Network discovered several exploits for both vulnerabilities in the wild, including an exploit for the RCE one.

“We also caught several samples exploiting these vulnerabilities in the wild,” reads a blog post published by PaloAlto Network Unit42 researchers. “Figure 5 shows a POST request from one of the samples: “

Social Warfare zero-day PoC

The root cause of both flaws is the misuse of the is_admin() function in WordPress.

“The root cause of each of these two vulnerabilities is the same: the misuse of the is_admin() function in WordPress,” the researchers say in a blog post. “Is_admin only checks if the requested page is part of admin interface and won’t prevent any unauthorized visit.”

Experts found about 40,000 sites that are using the Social Warfare plugin, most of which are running a vulnerable version.

Vulnerable websites belong to many industries, such as education, finance sites, and news, experts highlighted that many of these sites receive high traffic.

“There are many exploits in the wild for the Social Warfare plugin and it is likely they will continue to be used maliciously. Since over 75 million websites are using WordPress and many of the high traffic WordPress websites are using the Social Warfare plugin, the users of those websites could be exposed to malware, phishing pages or miners.” concludes PaloAlto Network. “Website administrators should to update the Social Warfare plugin to 3.5.3 or newer version.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – WordPress, Social Warfare plugin)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/84487/hacking/social-warfare-zero-day.html