Threat Advisory

WooCommerce Wholesale Lead Capture Plugin Allows Unauthenticated Arbitrary File Uploads

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture Plugin, which allows unauthenticated arbitrary file uploads due to missing file type validation in all versions up to and including. This makes it possible for attackers to upload files with malicious extensions such a remote script resource, allowing remote code execution. The vulnerable plugin exposes an AJAX action that processes these uploads and is reachable by unauthenticated visitors.

The handler does check the uploaded file's extension against a list of allowed file types, but this list is read directly from the request rather than from the form's server-side configuration. An attacker can include php in their own list of allowed file types to bypass the restriction and upload a file with a remote script resource extension.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture Plugin, which allows unauthenticated arbitrary file uploads due to missing file type validation in all versions up to and including. This makes it possible for attackers to upload files with malicious extensions such a remote script resource, allowing remote code execution. The vulnerable plugin exposes an AJAX action that processes these uploads and is reachable by unauthenticated visitors.

The handler does check the uploaded file's extension against a list of allowed file types, but this list is read directly from the request rather than from the form's server-side configuration. An attacker can include php in their own list of allowed file types to bypass the restriction and upload a file with a remote script resource extension.[emaillocker id="1283"]

The impact of this vulnerability is severe, as it allows attackers to write a PHP webshell to the site and execute arbitrary code, which can be leveraged to create administrator accounts, exfiltrate data, or take complete control of the site. It's essential for users to update their sites with the latest patched version of WooCommerce Wholesale Lead Capture Plugin, version, as soon as possible.

RECOMMENDATION:

We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu