Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in a WordPress plugin that may affect certain themes, allowing for the deletion of files on the server. This could potentially lead to unauthorized code execution, data loss, or website disruption. The main concern is to determine if your environment utilizes the affected plugin or theme.
- Plugin allows unauthorized file deletion on servers.
- Affects WordPress themes and associated plugins.
- Confirm relevance and exposure to our environment.
Attack Path
How an attacker could exploit the issue
Attackers can exploit this vulnerability by sending requests to a specific function within the WooCommerce Designer Pro plugin. This function, which handles saving canvas designs, does not properly validate file paths, allowing unauthenticated users to specify any file or directory on the server for deletion. Successful exploitation could lead to the removal of critical files, potentially resulting in remote code execution, significant data loss, or the complete unavailability of the website.
- No authentication required.
- Triggers by sending malicious AJAX requests.
- Risk: File deletion, remote code execution, site unavailability.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to delete any file on the server. This is possible because the plugin does not properly validate file paths when saving design files, a function that can be accessed remotely.
- Arbitrary files on the server.
- Via an unauthenticated AJAX request.
- Remote code execution or site unavailability.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WooCommerce Designer Pro plugin, when used with the Pricom theme, is susceptible to arbitrary file deletion. Application owners, in conjunction with infrastructure and security teams, should prioritize identifying all instances of this plugin, assessing their business criticality and external reachability, and then coordinating remediation efforts.
- Application and infrastructure owners
- Verify plugin presence and reachability.
- Plan risk-based remediation.