Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Truelysell Core WordPress plugin allows unauthenticated attackers to change user passwords, potentially leading to administrator account takeover. The exploit requires knowledge of a specific page containing a shortcode, but if present, it could allow unauthorized access and control of WordPress sites.
- Unauthenticated attackers can change user passwords.
- Confirms plugin relevance and exposure on WordPress sites.
- Assess exposure and review plugin usage.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can gain administrative access to a WordPress site by exploiting a vulnerability in the Truelysell Core plugin. This is possible if the attacker can identify a page containing a specific shortcode, allowing them to bypass authorization checks and change user passwords, including those of administrators.
- No authentication needed to start.
- Bypass authorization to change passwords.
- Risk of administrator account takeover.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could change user passwords and gain control of administrator accounts on WordPress sites running the Truelysell Core plugin. This is possible when the attacker can identify a page containing the 'truelysell_edit_staff' shortcode, allowing them to bypass authorization and access system resources.
- WordPress administrator accounts at risk.
- Attacker could change user passwords.
- Potential takeover of affected sites.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in the Truelysell Core WordPress plugin, allowing unauthenticated arbitrary password changes, is a critical risk for any organization using the plugin. The primary responsibility for addressing this will likely fall on the teams managing the WordPress instances and the applications hosted on them, such as Web Application Teams or Platform Operations. The first crucial step is to identify all WordPress sites utilizing the Truelysell Core plugin, determine their exposure (especially if publicly accessible), and confirm ownership to initiate a coordinated response.
- Application owners should own the issue.
- Verify plugin presence and reachability.
- Plan remediation during the next maintenance window.