https://portswigger.net/daily-swig/wordpress-security-plugin-hide-my-wp-addresses-sql-injection-deactivation-flaws The Daily Swig [ ] ( ) ( ) ( ) ( ) ( ) ( ) ( ) ( ) Regions Hacking News Data Breaches Cyber-attacks Vulnerabilities Bug Bounties More About Africa Asia Europe Middle East Latin America North America Oceania View all US news APT focus Take a closer look at Iran's state-sponsored hacking groups Regions Latest Hacking News Hacking Tools Hacking Techniques Pen Testing Cloud Security Database Security Email Security Network Security View all hacking news Movers and shakers OWASP stirs up web app threat categories in 2021 Hacking news Latest Data Breaches Data Leak Organizations Enterprise Security View all data breach news In focus Software supply chain attacks - everything you need to know Data Breaches Latest Cyber-attacks Cybercrime Cyber Warfare DDoS Attacks Supply Chain Attacks View all cyber-attack news Special report North Korean cyber-threat groups become top-tier adversaries Cyber Attacks Latest Vulnerabilities Zero-Day News RCE XSS SQL Injection SSRF CSRF XS Leaks View all security vulnerability news I, robot Machine learning security vulnerabilities are a growing threat Vulnerabilities Bug Bounty News VDP News Research OSINT View all bug bounty news Bug Bounty Radar The latest programs for October 2021 Bug bounties Interviews Analysis Research Deep Dives Browsers Ransomware Phishing Malware Encryption Privacy Mobile IoT Policy and Legislation Machine learning DNS Open Source Hardware Authentication Events View all infosec industry news Cybersecurity conferences A schedule of events in 2021 and beyond More topics WordPress security plugin Hide My WP addresses SQL injection, deactivation flaws Adam Bannister 25 November 2021 at 14:02 UTC Updated: 25 November 2021 at 15:44 UTC WordPress Vulnerabilities Research Twitter WhatsApp Facebook Reddit LinkedIn Email Bugs deemed 'very easy to exploit as they require no prerequisites' WordPress security plugin Hide My WP addresses SQL injection, deactivation flaws Hide My WP, a popular WordPress security plugin, contained a serious SQL injection (SQLi) vulnerability and a security flaw that enabled unauthenticated attackers to deactivate the software. Now patched, the bugs were discovered during an audit of several plugins on a customer's website by Dave Jong, CTO of Patchstack, which protects WordPress websites from vulnerabilities and runs a WordPress-focused bug hunting platform. The SQLi "is pretty severe", Jong told The Daily Swig. "It allows anyone to extract information from the database, it has no prerequisites. A tool such as SQLmap could easily exploit this vulnerability." YOU MAY ALSO LIKE GoDaddy managed WordPress hosting service breach exposed 1.2m user profiles The other vulnerability is less severe, "but could, under the right conditions, cause a malicious user to continue exploitation of a different vulnerability", added Jong. Both flaws are "very easy to exploit as they require no prerequisites", he warned. SQLi in SQLi defense software Claiming more than 26,000 customers, Hide My WP hides WordPress installations from malicious hackers, spammers, and theme detectors by various means. The plugin, which includes a feature that blocks SQLi and XSS attacks, itself contained an SQLi bug because of how the IP address was retrieved and used within SQL queries. "The function hmwp_get_user_ip tries to retrieve the IP address from multiple headers, including IP address headers which can be spoofed by the user such as X-Forwarded-For," reads a blog post published by Jong yesterday (November 24). "By supplying a malicious payload in one of these IP address headers, it will be directly inserted into the SQL query which makes SQL injection possible." Reset token Meanwhile, a reset token - hmwp_reset_token - "will be directly printed onto the screen which can then be used to deactivate the plugin in the file /wp-content/plugins/hide_my_wp/d.php (located in the root folder of the plugin)," explained Jong, adding the caveat that there must be a valid token with a non-empty value. Read more of the latest WordPress security news "Simply by visiting a URL such as /wp-admin/admin-ajax.php? die_message=new_admin&action=heartbeat we can make it display the reset token on the screen," he added. 'Positive news' Jong said he discovered the vulnerability, notified the plugin's developer, wpWave, and released a 'virtual patch' to premium Patchstack users on September 29. On October 5, after wpWave failed to respond, he alerted Envato, which responded within minutes and promptly removed the plugin, temporarily, from its codecanyon.net marketplace. Jong praised wpWave for rapidly addressing both flaws in Hide My WP version 6.2.4, released on October 26. "I would like to stress that such security improvements should be covered as positive news for the [open source] ecosystem," he said. "The fact that you haven't heard about a vulnerability being fixed in some other plugins doesn't mean the vulnerabilities aren't there - but might mean they are just not addressed." Patchstack's CTO invited other researchers and developers to report any bugs found in WordPress plugins to Patchstack's WordPress plugin-specific bounty program. RECOMMENDED Interview: Patchstack's Oliver Sild on securing WordPress, one plugin vulnerability at a time WordPress Vulnerabilities Research SQL Injection Denial of Service Database Security Data Leak Hacking News Hacking Techniques Hacking Tools PHP Open Source Software Pen Testing Secure Development Organizations Industry News XSS Authentication Adam Bannister Adam Bannister @Ad_Nauseum74 Twitter WhatsApp Facebook Reddit LinkedIn Email This page requires JavaScript for an enhanced user experience. Latest Posts Ukrainian police expose international phone-hacking gang 26 November 2021 Ukrainian police expose international phone-hacking gang 'Phoenix' group laid low following seizure of computing equipment and stolen devices Bloated browser? Microsoft pushes ahead with controversial 'buy now, pay later' feature for Edge 26 November 2021 Bloated browser? Microsoft pushes ahead with controversial 'buy now, pay later' feature for Edge Maritime giant Swire Pacific Offshore suffers data breach 26 November 2021 Maritime giant Swire Pacific Offshore suffers data breach Organization said it suffered 'unauthorized access' to systems Related stories This page requires JavaScript for an enhanced user experience. Ukrainian police expose international phone-hacking gang 26 November 2021 Ukrainian police expose international phone-hacking gang 'Phoenix' group laid low following seizure of computing equipment and stolen devices Bloated browser? Microsoft pushes ahead with controversial 'buy now, pay later' feature for Edge 26 November 2021 Bloated browser? Microsoft pushes ahead with controversial 'buy now, pay later' feature for Edge Maritime giant Swire Pacific Offshore suffers data breach 26 November 2021 Maritime giant Swire Pacific Offshore suffers data breach Organization said it suffered 'unauthorized access' to systems HTTP request smuggling New differential fuzzing tool reveals novel techniques 25 November 2021 HTTP request smuggling New differential fuzzing tool reveals novel techniques Burp Suite Web vulnerability scanner Burp Suite Editions Release Notes Vulnerabilities Cross-site scripting (XSS) SQL injection Cross-site request forgery XML external entity injection Directory traversal Server-side request forgery Customers Organizations Testers Developers Company About PortSwigger News Careers Contact Legal Privacy Notice Insights Web Security Academy Blog Research The Daily Swig PortSwigger Logo Follow us (c) 2021 PortSwigger Ltd.