multiple WordPress plugins: embedded malicious PHP code (CVE-2024-6297) #shorts #breaking

CVE

CVE-2024-6297 highlights a critical vulnerability in multiple WordPress plugins, notably including Social Warfare, Contact Form 7 Multi-Step Addon, Simply Show Hooks, Wrapper Link Elementor, and BLAZE Retail Widget. Discovered 0 months ago, this zero-day vulnerability involves the injection of malicious PHP code into the plugins. The compromised code allows attackers to exfiltrate database credentials and create unauthorized administrator users. As a result, WordPress plugin users are at high risk. The exploit has already affected several users, necessitating immediate attention from all individuals and organizations utilizing these plugins.

Watch the full video on YouTube: CVE-2024-6297

Remediation and exploitation details

This chain involves the following actors

This following systems are involved

Attack entry point

Remediation actions

Exploitation actions

Related Content

NOTE: The following related content has not been vetted and may be unsafe.

CVE database technical details

CVE ID
CVE-2024-6297
Description
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
Provider
Wordfence
CWE / problem types
CWE-506 Embedded Malicious Code
Affected Software Versions
warfareplugins:Social Sharing Plugin – Social Warfare:[{'version': '4.4.6.4', 'status': 'affected', 'lessThanOrEqual': '4.4.7.1', 'versionType': 'semver'}],themerex:Contact Form 7 Multi-Step Addon:[{'version': '1.0.4', 'status': 'affected', 'lessThanOrEqual': '1.0.5', 'versionType': 'semver'}],stuartobrien:Simply Show Hooks:[{'version': '1.2.1', 'status': 'affected', 'lessThanOrEqual': '1.2.2', 'versionType': 'semver'}],pedrogusmao02:Wrapper Link Elementor:[{'version': '1.0.2', 'status': 'affected', 'lessThanOrEqual': '1.0.3', 'versionType': 'semver'}],blazeretail:BLAZE Retail Widget:[{'version': '2.2.5', 'status': 'affected', 'lessThanOrEqual': '2.5.2', 'versionType': 'semver'}]
Date Published
2024-06-25T03:30:37.970Z
Last Updated
2024-08-01T21:33:05.337Z