Five WordPress Security Problems You Don’t Want to Ignore

Everyone and their dog has created a website using WordPress (even us!), but that doesn’t mean its inheritently secure.

WordPress administrators have been handed another compelling reason to check the updates page.

Security researchers have disclosed five critical WordPress vulnerabilities affecting WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP.

These are not minor bugs that make a button look slightly odd. Successful exploitation could potentially allow attackers to become administrators or, in some cases, execute malicious code on the underlying server.

What’s Affected?

WPMU DEV Dashboard versions up to 5.0.1 contain an authentication bypass issue affecting certain sites using Hub Single Sign-On. Under the right conditions, an unauthenticated attacker could gain administrator access.

The popular Avada theme is affected by a critical arbitrary file-write vulnerability involving installations running affected versions of Fusion Builder. Attackers could potentially upload and execute malicious PHP files.

TranslatePress versions up to 3.3.1 have a vulnerability that, under specific configuration conditions, could expose administrator password-reset information.

The Pods plugin versions up to 3.3.9 contain a privilege-escalation weakness allowing an attacker to potentially grant themselves administrator privileges or change another user’s password.

Then there is GiveWP, where the vulnerability received a perfect, yet very unwanted, CVSS score of 10.0.

Affected GiveWP installations could potentially allow attackers to execute commands remotely when particular donation-form and payment-gateway conditions are present.

What Should Website Owners Do?

If you run any of these products, check the versions currently installed and update beyond the affected releases as soon as compatible security fixes are available.

Backups should also be checked, administrator accounts reviewed and unusual site changes investigated.

WordPress itself is not necessarily the problem. The enormous ecosystem surrounding it means plugins and themes can significantly expand a site’s attack surface.

The update notification may be annoying.

A complete website takeover is generally considered slightly more annoying.