Rewterz

Rewterz Threat Alert – Malware Campaign Associated With EmpireMonkey Group

March 18, 2019
Rewterz

Rewterz Threat Alert – STOP Ransomware has a New Feature – Azorult

March 19, 2019

Rewterz Threat Advisory – WordPress Comment Cross-Site Request Forgery Vulnerability

Severity

Low

Analysis Summary

CVE-2019-9787
WordPress  does not properly filter comment content, leading to remote code execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because search engine optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.

Impact

Cross site scripting

Affected Products

WordPress 5.x
The vulnerability is reported in versions prior to 5.1.1.

Remediation

Update to version 5.1.1.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.