Vulnerability exploited in the wild
On September 6, late evening, the Wordfence Threat intelligence team discovered a vulnerability being actively exploited in BackupBuddy, a WordPress login that has around 140,000 active installations.
The vulnerability allows unauthorised users to download arbitrary from the compromised site which may have sensitive data. It impacts versions 184.108.40.206 to 220.127.116.11, and was fully fixed by September 2, 2022, in version 8.7.5.
Because of the fact that it is an actively exploited vulnerability, experts recommend users make sure that their site is updated to the latest fixed version 8.7.5 which iThemes has made available to all site owners using a vulnerable version regardless of the licence status.
About the vulnerability
The BackupBuddy plugin for WordPress is made to make backup management easy for owners of WordPress sites. One of the plugin features is storing backup files in various different locations, like AWS, Google Drive, and OneDrive.
There is also an option to store backup downloads locally through the “Local Directory Copy” option. Sadly, the process to download these locally stored files was not executed safely, which can allow unauthorised users to download any file that is stored on the server.
How is the vulnerability exploited?
Notably, the plugin registers an admin_init hook for the function aimed to download local backup files and the process itself lacks any nonce validation or capability checks.
It means that the function can be activated via any administrative page, this includes the ones that can be called without any verification, allowing unauthorised users to call the function.
The backup location isn’t validated; thus, an arbitrary file could be sneaked and downloaded.
Because of this vulnerability being exploited in the wild, due to its ease of exploitation, Wordfence has shared some details about the vulnerability.
How to stay safe?
Wordfence suggests for looking up the ‘local download ‘or the ‘local-destination-id’ parameter when checking requests in your access logs. “Presence of these parameters along with a full path to a file or the presence of ../../ to a file indicates the site may have been targeted for exploitation by this vulnerability,” it says.
If the site is breached, it may mean that BackupBuddy was the reason for the breach.
In its report, Wordfence concludes:
“we detailed a zero-day vulnerability being actively exploited in the BackupBuddy plugin that makes it possible for unauthenticated attackers to steal sensitive files from an affected site and use the information obtained in those files to further infect a victim. This vulnerability was patched yesterday and we strongly recommend updating to the latest version of the plugin, currently version 8.7.5.”
Read the full article here