Mistape 1.4.0 - Backdoor

2022-02-28 00:00
Anonymous

Strategic Overview

Status
Unpatched
Affected PluginMistape
Affected Version1.4.0
CVSS9.8Critical
CVEN/A
View all Mistape vulnerabilities

Vulnerability Overview

The Mistape plugin for WordPress is vulnerable to a developer-created backdoor in version 1.4.0. The backdoor is present in the report_stats() function, when the 'cmb' parameter is set to 'user', the plugin then looks for the first administrative user in the database and logs the person making the request in as that user. This makes it possible for an attacker to log in as an administrator without knowing information about users on the site. In addition, the function also makes Remote Code Execution possible, if the attacker has the ability to upload files to the server.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C