Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in a WordPress plugin that allows for permanent deletion of website content. This issue, stemming from improper authorization checks, enables unauthenticated attackers to remove various attachments, such as product images or logos, by exploiting a public review form. The main concern is confirming if this plugin is in use and if such content is exposed.
- Unauthenticated attackers can delete arbitrary website files.
- Critical content loss is possible; verify plugin usage.
- Confirm exposure and assess impact on business assets.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by leveraging a public review form link to bypass authorization checks. This allows them to submit review data containing crafted IDs, which, when later processed for deletion, results in the permanent removal of arbitrary files from the website's media library.
- Public review form link is accessible.
- Attacker crafts review with attachment IDs.
- Arbitrary file deletion occurs.
Live Threat
Current exploitation, exposure, and threat context
The Customer Reviews for WooCommerce plugin's authorization bypass vulnerability could allow unauthenticated attackers to delete any attachment from the WordPress Media Library. This risk exists when a public review form link is accessible, enabling the attacker to inject attachment IDs into a review that is later purged.
- Arbitrary attachments in Media Library.
- Unauthenticated deletion via public review form.
- Permanent loss of administrator-owned content.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Customer Reviews for WooCommerce plugin on WordPress sites is vulnerable, allowing unauthenticated attackers to delete arbitrary attachments. Action is required by the website owner or platform administrator responsible for managing WordPress plugins and their associated media library. The initial step involves identifying all instances of the affected plugin, confirming exposure via public review forms, and assessing the business criticality of the stored attachments to prioritize remediation efforts.
- Website owners and platform administrators own this issue.
- Verify public review form exposure and critical media.
- Plan remediation based on confirmed risk and impact.