Rewterz
Rewterz Threat Alert – Middle Eastern Governments Targeted in Phishing Campaigns with IronWind Malware – Active IOCsc
November 14, 2023
Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
November 15, 2023

Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-4775 CVSS:6.4

Advanced iFrame plugin for WordPress is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-47652 CVSS:7.1

Auto Affiliate Links Plugin for WordPress is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.

CVE-2023-47228 CVSS:5.9

Layer Slider Plugin for WordPress is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-47230 CVSS:5.4

Contact Forms by Cimatti Plugin for WordPress is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.

CVE-2023-47231 CVSS:6.4

ShortCodes UI Plugin for WordPress is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability using ‘plugin_delete_me’ shortcode to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-47237 CVSS:5.4

WP Google My Business Auto Publish plugin for WordPress is vulnerable to cross-site request forgery, caused by improper validation of user-supplied. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.

CVE-2023-47238 CVSS:4.3

Top 10 Plugin Plugin for WordPress is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.

Impact

  • Cross-Site Scripting
  • Gain Access

Indicators Of Compromise

CVE

  • CVE-2023-4775
  • CVE-2023-47652
  • CVE-2023-47228
  • CVE-2023-47230
  • CVE-2023-47231
  • CVE-2023-47237
  • CVE-2023-47238

Affected Vendors

WordPress

Affected Products

  • Advanced iFrame Plugin for WordPress 2023.8
  • Auto Affiliate Links Plugin for WordPress 6.4.2.4
  • Layer Slider plugin for WordPress 1.1.9.7
  • Contact Forms by Cimatti Plugin for WordPress 1.6.0
  • ShortCodes UI Plugin for WordPress 1.9.8
  • WP Google My Business Auto Publish Plugin for WordPress 3.7
  • Top 10 Plugin for WordPress 3.3.2

Remediation

Refer to WordPress Plugins Directory for patch, upgrade or suggested workaround information.

CVE-2023-4775

CVE-2023-47652

CVE-2023-47228

CVE-2023-47230

CVE-2023-47231

CVE-2023-47237

CVE-2023-47238