PT-2020-20254 · WordPress+1 · Wordpress+1
Published
2020-02-06
·
Updated
2020-02-07
·
CVE-2020-8658
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BestWebSoft Htaccess plugin versions prior to 1.8.2
Description
The issue allows for Cross-Site Request Forgery (CSRF) attacks due to incorrect validation of the
htccss nonce name flag, which is supposed to pass a nonce to WordPress for anti-CSRF protection. This incorrect implementation enables an attacker to direct a victim to a malicious webpage, modifying the .htaccess file and potentially taking control of the website. The attack exploits the "wp-admin/admin.php?page=htaccess.php&action=htaccess editor" endpoint.Recommendations
For BestWebSoft Htaccess plugin versions prior to 1.8.2, update to version 1.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp-admin/admin.php?page=htaccess.php&action=htaccess editor endpoint to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bestwebsoft Htaccess
Wordpress