Wordpress Responsive theme: arbitrary HTML content injection (CVE-2024-2848)

Related Vulnerabilities: CVE-2024-2848  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Wordpress Responsive theme: arbitrary HTML content injection (CVE-2024-2848)

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Hanno Böck &lt;hanno () hboeck de&gt;

Date: Mon, 22 Apr 2024 12:52:17 +0200

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
A Wordpress theme called "Responsive" had a vulnerability that allowed
injecting arbitrary content into the page's footer. This is fixed in
version 5.0.3.

There are active attacks exploiting this vulnerability, redirecting
page visitors to malicious websites.
If you have to cleanup an affected installation, the attack can, as
far as I understand, only set the "footer-copyright" option stored
in the options table (usually wp_options). So you can check
the fielt with option_name=footer-copyright and remove any malicious /
spammy content.

Advisory:
https://github.com/advisories/GHSA-8vpf-jx6q-39fr

Quote:
"The Responsive theme for WordPress is vulnerable to unauthorized
modification of data due to a missing capability check on the
save_footer_text_callback function in all versions up to, and
including, 5.0.2. This makes it possible for unauthenticated attackers
to inject arbitrary HTML content into the site's footer."

Upstream changelog:
https://themes.svn.wordpress.org/responsive/5.0.3/changelog.txt
"(28/03/2024) = Fix - Version 5.0.3
[...]
[!] = Fixed = Fixed the vulnerability of unauthorized modification of
footer text."

The latest version 5.0.3.1 contains another possibly relevant note in
the changelog:
"(17/04/2024) = Fix - Version 5.0.3.1
[!] = Fixed = Enhanced Security: Strengthened the codebase to further
protect your website."

I have not verified whether this is another vulnerabiltiy or just
additional hardening.

-- 
Hanno Böck
https://itsec.hboeck.de/

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

Wordpress Responsive theme: arbitrary HTML content injection (CVE-2024-2848) Hanno Böck (Apr 22)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->