Securi disclosed the issue and the known affected plugins.
This particular exploit could be done on the front end in some plugins while others required admin login. But the issue actually can be attributed to unclear information in the WordPress Codex that led to developers inadvertantly leaving the XSS vulnerability. Yoast also talks about the issue in their plugin, and how it was discovered and responsibly disclosed to them.
Here is the full list of known WordPress plugins affected by this issue.
- Jetpack
- WordPress SEO
- Google Analytics by Yoast
- All In one SEO
- Gravity Forms
- Multiple Plugins from Easy Digital Downloads
- UpdraftPlus
- WP-E-Commerce
- WPTouch
- Download Monitor
- Related Posts for WordPress
- My Calendar
- P3 Profiler
- Give
- Multiple iThemes products including Builder and Exchange
- Broken-Link-Checker
- Ninja Forms
What is interesting about this case is that all these plugin developers worked together in order to push the updates at the same time, which reduced the chance hackers would see the first one updated and could go and exploit the other plugins with the same vulnerability that hadn’t been updated yet.
Users should update the above plugins immediately. It is also a good idea to update all plugins, as some smaller plugins could have this vulnerability but weren’t identified as being affected.
This is the latest in a string of recently discovered WordPress plugin exploits, including Google Analytics by Yoast, SEO by Yoast, Shareaholic, RevSlider and Fancybox-for-Wordpress.
It is always best to update plugins immediately when a new one is available or have it done automatically. While this was publicized, often developers will quietly update to close exploits without detailing why, leaving many webmasters with vulnerable plugins which haven’t been updated.
Jennifer Slegg
Latest posts by Jennifer Slegg (see all)
- 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates - August 1, 2022
- Google Quality Rater Guidelines: The Low Quality 2021 Update - October 19, 2021
- Rethinking Affiliate Sites With Google’s Product Review Update - April 23, 2021
- New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met - October 16, 2020
- Google Updates Experiment Statistics for Quality Raters - October 6, 2020