Threat Advisory

Two Vulnerabilities Discovered in POST SMTP Mailer WordPress Plugin

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A critical vulnerability has been identified in the POST SMTP Mailer WordPress plugin, a widely used email delivery tool employed by approximately 300,000 websites. The first vulnerability, tracked as CVE-2023-6875, involves a severe authorization bypass flaw resulting from a "type juggling" issue on the connect-app REST endpoint. An unauthenticated attacker can exploit this flaw to reset the API key and gain access to sensitive log information, including password reset emails. By manipulating a function related to the mobile app, the attacker can set a valid token with a zero value for the authentication key, subsequently triggering a password reset for the site's admin. Subsequently, the attacker accesses the key from within the application, changing it and effectively locking the legitimate user out of the account. With administrator privileges obtained through this exploit, the attacker can exercise complete control over the site, potentially planting backdoors, modifying plugins and themes, editing, and publishing content, or redirecting users to malicious destinations.[/subscribe_to_unlock_form]

Summary:

A critical vulnerability has been identified in the POST SMTP Mailer WordPress plugin, a widely used email delivery tool employed by approximately 300,000 websites. The first vulnerability, tracked as CVE-2023-6875, involves a severe authorization bypass flaw resulting from a "type juggling" issue on the connect-app REST endpoint. An unauthenticated attacker can exploit this flaw to reset the API key and gain access to sensitive log information, including password reset emails. By manipulating a function related to the mobile app, the attacker can set a valid token with a zero value for the authentication key, subsequently triggering a password reset for the site's admin. Subsequently, the attacker accesses the key from within the application, changing it and effectively locking the legitimate user out of the account. With administrator privileges obtained through this exploit, the attacker can exercise complete control over the site, potentially planting backdoors, modifying plugins and themes, editing, and publishing content, or redirecting users to malicious destinations.[emaillocker id="1283"]

The second vulnerability, identified as CVE-2023-7027, is a cross-site scripting (XSS) issue resulting from insufficient input sanitization and output escaping. This vulnerability enables attackers to inject arbitrary scripts into the web pages of the affected site, potentially compromising user interactions and sensitive data. This could lead to a range of malicious activities, including the theft of sensitive information or the redirection of users to malicious sites. The combination of these vulnerabilities poses a significant threat to the security of impacted WordPress websites, allowing unauthorized individuals to take control of site authentication, potentially compromising sensitive data, and engaging in malicious activities.

Recommendations:

  • We strongly recommend you update POST SMTP Mailer WordPress plugin to version 2.8.9.

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/over-150k-wordpress-sites-at-takeover-risk-via-vulnerable-plugin/

[/emaillocker]
crossmenu