WordPress Cookie Integrity Protection Allows Unauthorized Access
WordPress is prone to a vulnerability that allows an attacker to gain unauthorized access. An attacker, who is able to register a specially crafted username on a WordPress installation, is able to generate authentication cookies for other chosen accounts, including admin account. If a WordPress blog is configured to freely permit account creation, a remote attacker can gain WordPress-administrator access and then elevate this to arbitrary code execution as the web server user.
An attacker wishing to exploit this vulnerability would create an unprivileged account with its username starting with “admin”. The cookie returned on logging into this account can then be manipulated so as to be valid for the administrator account.
Successfully exploiting this issue will compromise the affected application. Attackers can use a browser to exploit this issue.
Versions prior to WordPress 2.5.1 are vulnerable.
Solutions:
1.Upgrade to WordPress 2.5.1
2. De-select “Anyone can register” in the Membership section of “General Settings” to disable new accounts creation.
More on CyberInsecure:
Leave a Reply
Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.