Ad Inserter Pro <= 2.7.15 - Arbitrary File Modification

2022-06-28 00:00
Anonymous

Strategic Overview

Status
Patched in 2.7.16
Affected PluginAd Inserter Pro
Affected Version<= 2.7.15
CVSS8.1High
CVEN/A
View all Ad Inserter Pro vulnerabilities

Vulnerability Overview

The Ad Inserter Pro plugin for WordPress is vulnerable to Arbitrary File Modification in versions 2.7.15 via unknown mechanisms. The Wordfence Threat Intelligence team conducted a thorough review of the vulnerable plugin and could not determine a vulnerable component in the plugin, which leads us to believe there may have been some element on the plugin developers management side that may have made file modification possible without the appropriate authorizations. Reports indicate that attackers were deleting wp-config.php files to reset the site, which leads us to believe the vulnerability made arbitrary file deletion or modification possible.

Technical Analysis

REMEDIATION: Update to version 2.7.16, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C