PT-2020-20254 · WordPress+1 · Wordpress+1

Published

2020-02-06

·

Updated

2020-02-07

·

CVE-2020-8658

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BestWebSoft Htaccess plugin versions prior to 1.8.2
Description The issue allows for Cross-Site Request Forgery (CSRF) attacks due to incorrect validation of the htccss nonce name flag, which is supposed to pass a nonce to WordPress for anti-CSRF protection. This incorrect implementation enables an attacker to direct a victim to a malicious webpage, modifying the .htaccess file and potentially taking control of the website. The attack exploits the "wp-admin/admin.php?page=htaccess.php&action=htaccess editor" endpoint.
Recommendations For BestWebSoft Htaccess plugin versions prior to 1.8.2, update to version 1.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp-admin/admin.php?page=htaccess.php&action=htaccess editor endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8658

Affected Products

Bestwebsoft Htaccess
Wordpress