Wordfence PRISM has identified a serious Authentication Bypass vulnerability in the Advanced Responsive Video Embedder plugin, affecting approximately 20,000 active installations. This backdoor allows unauthenticated attackers to gain full administrative control over WordPress sites with a single HTTP request.
Key Takeaways
- Critical vulnerability in Advanced Responsive Video Embedder allows full admin access.
- Attackers can exploit this with just one HTTP request.
- Immediate uninstallation of the plugin is recommended for all users.
Details of the Vulnerability
The vulnerability exists in version 10.8.7 of the plugin, where a hardcoded token can be used to bypass authentication. This is not a simple coding error but a deliberate supply chain attack. If exploited, it can lead to full site compromise without any credentials or user interaction required.
Recommendations for Users
Users are strongly urged to uninstall the Advanced Responsive Video Embedder plugin immediately to protect their sites. If you have used this plugin, check for unauthorized changes, audit your site, and consider rotating your WordPress secret keys as a precaution.
Importance of Monitoring Plugins
This incident highlights the growing threat of supply chain attacks on WordPress plugins. Regularly auditing your plugins and staying updated on security issues is crucial for maintaining site security.
Frequently Asked Questions
What vulnerability was detected in the Advanced Responsive Video Embedder plugin?
A critical Authentication Bypass vulnerability was identified, allowing unauthenticated attackers to gain full administrative access.
What should users do to protect their WordPress sites?
Users are strongly urged to uninstall the Advanced Responsive Video Embedder plugin immediately.
What are the implications of this vulnerability?
Exploitation of this vulnerability can lead to full site compromise without any credentials or user interaction required.
Why is monitoring plugins important?
This incident highlights the growing threat of supply chain attacks, making regular audits and updates essential for site security.