Five WordPress Plugins Just Handed Out Admin Keys

Five WordPress Plugins Just Handed Out Admin Keys

Somewhere out there, a WordPress site owner is sipping coffee, blissfully unaware that their donation form, their translation widget, and their theme builder all just became welcome mats for strangers. Five critical vulnerabilities, five popular plugins, one very bad week for WordPress admins who haven't clicked "update" lately.

The Lineup Nobody Wanted

Security researchers disclosed five separate critical flaws across WPMU DEV Dashboard, the Avada theme, TranslatePress, Pods, and GiveWP — all rated CVSS 9.8 or higher, which in vulnerability-speak means "please stop reading this and go patch." WPMU DEV Dashboard's flaw lets an unauthenticated attacker walk into administrator access on SSO-enabled sites, while Avada's arbitrary file-write bug can be chained into full remote code execution.

TranslatePress leaks plaintext password-reset URLs to anyone who asks nicely, Pods allows privilege escalation up to Administrator, and GiveWP — used by countless nonprofits to collect donations — has a CVSS 10.0 bug that enables remote code execution on any site with one active payment gateway. That's the maximum severity score. There is no higher.

The Part Everyone Forgets

These aren't obscure plugins nobody's heard of — Avada is one of the best-selling WordPress themes ever sold, and GiveWP powers donation flows for organizations that really cannot afford a breach. Critical flaws in mainstream, trusted software are exactly the ones that do the most damage, because "everyone uses it" also means "everyone's a target."

The fixes exist — Avada 7.16.1, TranslatePress 3.3.2, Pods 3.3.9.1, GiveWP 4.16.7.2, WPMU DEV Dashboard 5.0.2 — which means the only thing standing between a site and a headline is whether someone actually runs the update. History suggests a lot of someones won't.

Patch Tuesday gets the fanfare, but it's these quiet plugin advisories that separate the sites still standing next month from the ones explaining a breach to their board.

If your site runs on plugins you can't remember the last time you audited, WTK's free security checklist is a solid place to start closing the gaps — grab it here.

Source: The Hacker News