Ad Inserter Wordpress RCE-Vulnerablity details.

Security researchers at Wordfence discovered a critical vulnerability in the Inserter WordPress plugin that could be exploited by authenticated attackers to remotely execute PHP code.

What is AdInserter all about :
     it is an Ad management plugin that allows administrators to benefit of advanced features to insert ads at optimal positions. It supports major ad programs, including Google AdSense, Google Ad Manager(DFP – DoubleClick for publishers), contextual Amazon Native Shopping Ads, Media.net and rotating banners.

How many hosts probably might infected :

   Running a quick shodan query shows minimal 20,000 hosts might be infected.
 
   Google Dork to find vulnerable wordpress would be :
 
  "inurl:wp-content/plugins/adinserter/"
 
 
 
Proof of concept :







Mitigation :

Update your plugins.

Comments

Popular Posts