Attackers are actively exploiting stored cross-site scripting (XSS) flaws in two unrelated WordPress plugins — Ninja Forms and WPC Product Bundles for WooCommerce — to install backdoors and create rogue administrator accounts, BleepingComputer reports.
The striking detail is that the two plugins are not connected in any operational sense: separate maintainers, separate codebases, no shared deployment path. What unites them is the attacker's strategy, not the vendor's. Threat actors are treating the WordPress plugin ecosystem as interchangeable infrastructure — scanning for whichever vulnerable extension a target happens to run, rather than pursuing a specific product or vendor. One vulnerable install is one compromised site.
Both flaws follow the same mechanism. Attacker-controlled script is written into the site's database and sits there quietly until an authenticated administrator views the affected page, at which point the script executes inside the admin's own session. The attacker inherits every privilege that account holds: creating users, installing plugins, editing theme files, disabling security tooling. That makes the payload unusually durable — it requires no further interaction beyond routine admin activity, and the observed post-exploitation behaviour reflects it, with backdoor files planted for persistent access and rogue admin accounts created as a fallback should the original injection route be closed.
Operators should treat patching as an immediate task rather than a maintenance-window item. BleepingComputer does not publish patch versions for either plugin in its reporting; teams should check the plugins' own changelogs or release pages, not secondary coverage, to confirm what fixed build to install. And verifying that a managed host offers automatic plugin updates is not the same as verifying that a fix has landed — deployment policies vary widely, and enterprise estates often deliberately delay updates pending compatibility checks. Confirm installed versions directly in the WordPress admin panel.
Patching ends the injection vector. It does not undo what was done through it. Any site believed to have been affected should assume compromise:
- Review the admin user list for unfamiliar accounts and delete or disable them.
- Scan
wp-content, including upload directories, for unexpected PHP files and injected payloads. - Revoke all active sessions and force password resets for every administrator and editor.
- Rotate credentials, including database passwords and any API keys tied to the site.
- If compromise cannot be ruled out, rebuild from a clean backup taken before the suspected intrusion window rather than attempting to sanitise a compromised installation in place.
The wider lesson for anyone running WordPress at scale: the plugin registry is the attack surface, not an afterthought. Keep the plugin footprint to the minimum genuinely required, enforce two-factor authentication on every administrative account, and run file-integrity monitoring on wp-content so unauthorised PHP drops surface in hours rather than during a quarterly audit.
Source: BleepingComputer.
據 BleepingComputer 報道,黑客正積極利用兩個互不相關的 WordPress 外掛程式——Ninja Forms 及 WPC Product Bundles for WooCommerce——中的儲存式跨站腳本(stored cross-site scripting,XSS)漏洞,用以安裝後門及建立惡意管理員帳戶。
值得注意的是,這兩個外掛程式在運作層面並無任何關聯:開發者各異、程式碼庫各自獨立,亦沒有共用的部署路徑。將它們串連在一起的是攻擊者的策略,而非供應商本身。威脅行為者正把 WordPress 外掛程式生態系統視為可互相替換的基礎架構——他們掃描目標站點剛好安裝的任何有漏洞外掛,而非針對特定產品或供應商下手。一個有漏洞的安裝,就等於一個已被入侵的網站。
兩個漏洞均遵循相同的機制。由黑客控制的 script 會被寫入網站的資料庫,靜靜地潛伏,直至某位已登入的管理員瀏覽受影響的頁面,script 隨即在該管理員自身的 session 內執行。攻擊者因此獲得該帳戶所擁有的全部權限:建立使用者、安裝外掛程式、編輯主題檔案、關閉安全工具。這令惡意程式碼格外頑固——它只需管理員的日常操作即可觸發,無須任何額外互動;而觀測到的入侵後行為亦反映了這一點:後門檔案被植入以維持持久存取權限,同時建立惡意管理員帳戶作為後備方案,以防原有注入途徑被堵上。
營運團隊應把修補視為即時任務,而非維護時段的例行項目。BleepingComputer 的報導並未提供兩個外掛程式的修補版本;團隊應查閱各外掛程式自身的 changelog 或發佈頁面(而非二手報導),以確認應安裝哪個修復版本。此外,託管主機聲稱「提供」自動更新外掛功能,與實際上「已完成」修補是兩回事——部署政策差異甚大,企業環境往往會刻意延遲更新,以待相容性檢查完成。應直接在 WordPress 後台管理介面核實已安裝的版本。
修補可堵上注入途徑,但無法抹去已經造成的後果。 任何懷疑曾受影響的網站,均應假設已被入侵:
- 檢查管理員使用者名單,找出不熟悉的帳戶並予以刪除或停用。
- 掃描
wp-content(包括上載目錄)中的可疑 PHP 檔案及注入的惡意程式碼。 - 撤銷所有現存 session,並強制所有管理員及編輯者重設密碼。
- 輪換所有相關憑證,包括資料庫密碼及與該網站相關的任何 API key。
- 如無法排除已被入侵,應使用可疑入侵時段之前的乾淨備份重建站點,而非嘗試就地清理已被污染的安裝。
對大規模營運 WordPress 的人士而言,更廣泛的教訓是:外掛程式註冊庫本身就是攻擊面,而非事後才考慮的項目。應將外掛程式的使用範圍縮減至真正必要的最低限度,在所有管理員帳戶強制啟用雙重驗證(two-factor authentication),並對 wp-content 執行檔案完整性監控,讓未經授權的 PHP 檔案在數小時內浮現,而非等到季度審計時才被發現。
來源:BleepingComputer。
