CVE-2024-12567 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

CVE-2024-12567 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

Email Subscribers by Icegram Express is a widely used WordPress plugin for collecting and managing email subscribers, as well as sending newsletters, notifications, and other updates. A critical Stored Cross-Site Scripting (XSS) vulnerability, CVE-2024-12567, has been discovered in this plugin. The vulnerability allows attackers to inject malicious JavaScript into form fields, which can lead to account takeover and the creation of a backdoor admin account. With over 100,000 active installations, this flaw represents a significant security risk to WordPress websites using the Email Subscribers plugin.

CVE-2024-12566 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

CVE-2024-12566 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

Email Subscribers by Icegram Express is a popular WordPress plugin that enables website owners to collect email subscribers and send newsletters, notifications, and updates. However, CVE-2024-12566 has been identified as a serious Stored Cross-Site Scripting (XSS) vulnerability within the plugin. This flaw allows attackers with editor-level access to inject malicious JavaScript code into a form’s “Show message” field. Once the malicious script is embedded, it can lead to session hijacking or the creation of a backdoor admin account. With over 100,000 active installations, this vulnerability poses a significant risk for WordPress websites using Email Subscribers by Icegram Express.

Plugin Security Certification (PSC-2024-64547): “Rank Math SEO” – Version 1.0.236: Use SEO with Enhanced Security

Plugin Security Certification (PSC-2024-64547): “Rank Math SEO” – Version 1.0.236: Use SEO with Enhanced Security

Rank Math SEO is a state-of-the-art plugin designed to simplify and enhance search engine optimization (SEO) for WordPress websites. Its use of artificial intelligence (AI) sets it apart, providing advanced tools to automate and optimize SEO tasks. However, alongside its powerful functionality, it is crucial to assess the plugin’s security practices to ensure safe deployment on websites.

Plugin Security Certification (PSC-2024-64546): “Polylang” – Version 3.6.6: Use Polyang with Enhanced Security

Plugin Security Certification (PSC-2024-64546): “Polylang” – Version 3.6.6: Use Polyang with Enhanced Security

The Polylang plugin is a powerful tool designed to create multilingual WordPress websites. With support for an unlimited number of languages, automatic integration with WordPress core features, and seamless performance, it has become a go-to solution for developers and site administrators alike. However, as with any plugin, security is paramount, and Polylang stands out for its commitment to safe coding practices.

CVE-2024-11636 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

CVE-2024-11636 – Email Subscribers by Icegram Express – Stored XSS to JS Backdoor Creation – POC

Email Subscribers by Icegram Express is a widely used WordPress plugin designed to help website administrators collect and manage email subscribers, as well as send newsletters and email notifications. However, a critical vulnerability has been found in the plugin, CVE-2024-11636, which allows attackers with editor-level access to inject malicious JavaScript into form fields. This stored Cross-Site Scripting (XSS) vulnerability can lead to account takeover by creating a backdoor that allows unauthorized users to gain full control of the site. With over 100,000 active installations, this flaw represents a serious security risk for WordPress sites using the plugin.

Plugin Security Certification (PSC-2024-64544): “reCaptcha by BestWebSoft” – Version 1.79: Use reCaptcha with Enhanced Security

Plugin Security Certification (PSC-2024-64544): “reCaptcha by BestWebSoft” – Version 1.79: Use reCaptcha with Enhanced Security

The reCaptcha by BestWebSoft plugin is a robust security solution designed to protect WordPress forms from spam and bot-driven attacks. By integrating seamlessly with various forms, including login, registration, comments, and custom forms, the plugin ensures only legitimate users can access your website’s functionalities while blocking automated threats.

CVE-2024-10102 – Robo Gallery (Photo Gallery, Images, Slider in Rbs Image Gallery) – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10102 – Robo Gallery (Photo Gallery, Images, Slider in Rbs Image Gallery)      – Stored XSS to JS Backdoor Creation – POC

Robo Gallery, a popular WordPress plugin used for displaying photo galleries and sliders, contains a critical vulnerability, CVE-2024-10102. This flaw allows attackers to inject malicious JavaScript code into the plugin’s settings via a simple stored Cross-Site Scripting (XSS) attack. The vulnerability can be exploited by users with contributor privileges, enabling them to create a backdoor in the WordPress admin area. This backdoor can then be used to hijack admin accounts, potentially gaining full control of the website. With over 50,000 active installations, this vulnerability poses a significant risk to sites using Robo Gallery.

CVE-2024-10562 – Form Maker by 10Web – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10562 – Form Maker by 10Web – Stored XSS to JS Backdoor Creation – POC

Form Maker by 10Web is a widely used plugin for creating and managing forms in WordPress. However, a critical vulnerability, CVE-2024-10562, has been discovered in the plugin that allows for Stored Cross-Site Scripting (XSS) attacks. This flaw enables attackers with editor-level privileges to inject malicious JavaScript code into form settings, which is stored and executed when the form is rendered. The injected script can create a backdoor, allowing attackers to escalate their privileges and potentially gain full control over the site. With over 50,000 active installations, this vulnerability poses a significant security risk for WordPress websites using Form Maker by 10Web.

CVE-2024-10309 – Tracking Code Manager – Stored XSS to JS Backdoor Creation – POC

CVE-2024-10309 – Tracking Code Manager – Stored XSS to JS Backdoor Creation – POC

Tracking Code Manager, a widely used WordPress plugin by Data443, allows users to manage and customize third-party tracking codes and scripts on their WordPress sites. The plugin is known for its simplicity and compliance with privacy laws, offering features like tracking pixel placement, regional blocking, and seamless integration with e-commerce platforms. However, a critical stored Cross-Site Scripting (XSS) vulnerability has been identified in versions below 2.4.0, potentially exposing websites to serious security risks.

This vulnerability enables users with Contributor or higher roles to inject malicious scripts into the site, which can compromise the security and integrity of the affected WordPress installation. In this article, we’ll explore the discovery, exploitation, potential risks, and recommendations for mitigating this issue.