Wordpress Users, Beware – New Vulnerability Release

Posted 1597 days ago - Security, Wordpress

Milworm has announced a new exploit for the Wordpress Plugin, WP-Filemanager 1.2. The hole lets attackers upload pretty much anything they want, including evil PHP scripts.

For the details, check out: http://www.milw0rm.com/exploits/4844

If you don't use the WP-Filemanager plugin and your Wordpress installation is current, don't worry, you're in the clear. Otherwise, I highly recommend you uninstall the plugin all together, or j00r b0x will get pwned. It's times like this when I feel sorry for people with shared hosting accounts. Your site could fall victim to an attack because of some moron's inability to keep their site secure.

Please note, the exploit was released today, so there's still time, maybe. If you run WP-Filemanager 1.2, fix it now.

In addition, the following exploits were released and are available on Milworm's web-site:

  • PortalApp 4.0 (SQL/XSS/Auth Bypasses) Multiple Remote Vulnerabilities
  • XOOPS mod_gallery Zend_Hash_key + Extract RFI Vulnerability
  • Uebimiau Web-Mail Remote File Disclosure Vulnerability
  • RunCMS Newbb_plus <= 0.92 Client IP Remote SQL Injection Exploit
  • MODx CMS 0.9.6.1 Multiple Remote Vulnerabilities

Ahhh, what a great way to bring in the new year.

Word Count: 211

Tags: , ,

Click Here to Submit a Comment

Permalink / Last Modified:

Support Nullamatix.com:

See Also:

  • 01/30/2008 -- 2 More Wordpress Plugin Exploits – Adserve & WassUp
    Excerpt: "Wow, four Wordpress plugin exploits released in under a week. Are these plugin authors really amateurs, or just trying to pwn Wordpress blogs? First up, Adserve version 0.2. The SQL injection vulnerability resides in adclick.php. Here's the vulnerable ..."
  • 01/28/2008 -- 2 New Wordpress Plugin SQL Injection Vulnerabilities
    Excerpt: "That's right Wordpresss kiddies, two new vulnerabilities, and they're pretty nasty. Author Houssamix From H-T Team has released two remote SQL injection proof of concepts for WP-Cal and fGallery 2.4.1. The vulnerability for WP-Cal exists ..."
  • 01/20/2008 -- Another Wordpress Plugin Vulnerability: WP-Forum 1.7.4
    Excerpt: "Milworm.com has released another Wordpress plugin vulnerability, this time it's WP-Forum 1.7.4. I'm no expert at deciphering exactly how exploits work, but this remote sql injection appears to grant the attacker administrative privileges. If you're using ..."
  • 12/31/2007 -- Updates and a Happy New Year
    Excerpt: "A recently released Wordpress vulnerability proof of concept forced me to update Wordpress, and as a result, several plug-ins are now failing to work properly. I don't regret performing the update because not only were the security holes patched, but database ..."

Leave a Reply