Sydney Toolbox Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via _id – CVE-2024-2936 |WordPress Plugin Vulnerability Report
Plugin Name: Sydney Toolbox
Key Information:
- Software Type: Plugin
- Software Slug: sydney-toolbox
- Software Status: Active
- Software Author: athemes
- Software Downloads: 2,161,148
- Active Installs: 80,000
- Last Updated: April 1, 2024
- Patched Versions: 1.27
- Affected Versions: <= 1.26
Vulnerability Details:
- Name: Sydney Toolbox <= 1.26
- Title: Authenticated (Contributor+) Stored Cross-Site Scripting via _id
- Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- CVE: CVE-2024-2936
- CVSS Score: 6.4
- Publicly Published: March 28, 2024
- Researchers: Ngô Thiên An (ancorn_) - VNPT-VCI and Phuoc Pham (p3tl0v3r) - VNPT Cyber Immunity
- Description: The Sydney Toolbox plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in the _id attribute of widgets, present in all versions up to, and including, 1.26. This vulnerability arises due to insufficient input sanitization and output escaping on user-supplied attributes, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts that are executed when a user accesses an injected page.
Summary:
The Sydney Toolbox plugin for WordPress has a vulnerability in versions up to and including 1.26 that allows for Stored Cross-Site Scripting via the _id attribute in widgets. This vulnerability has been addressed and patched in version 1.27.
Detailed Overview:
This vulnerability, discovered by researchers Ngô Thiên An and Phuoc Pham, highlights a critical security flaw in the Sydney Toolbox plugin, specifically in the handling of the _id attribute of widgets. Attackers with at least contributor-level access could exploit this vulnerability to inject malicious scripts into web pages, compromising the security of the site and its users. The risks associated with this vulnerability include unauthorized data access, session hijacking, and potentially even site control, underscoring the urgent need for remediation.
Advice for Users:
- Immediate Action: Users of the Sydney Toolbox plugin should immediately update to the patched version 1.27 to mitigate the risk posed by this vulnerability.
- Check for Signs of Vulnerability: Website administrators should review their sites for any unusual or unauthorized content changes, which may indicate that the vulnerability has been exploited.
- Alternate Plugins: While the immediate risk has been addressed, users may consider exploring alternative plugins that offer similar functionality, especially if they have concerns about the plugin's security history.
- Stay Updated: It's crucial to keep all WordPress plugins up to date to protect against known vulnerabilities. Regular updates and security practices can significantly enhance the security of your WordPress site.
Conclusion:
The discovery and subsequent patching of the Stored Cross-Site Scripting vulnerability in the Sydney Toolbox plugin serve as an important reminder of the continuous need for vigilance in the digital space. The prompt action taken by the plugin developers to release a patched version reinforces the critical importance of maintaining up-to-date software. Users are encouraged to ensure their installations are updated to version 1.27 or later to safeguard against this vulnerability.
References:
- Wordfence Vulnerability Report for Sydney Toolbox <= 1.26
- Wordfence Vulnerabilities for Sydney Toolbox
Detailed Report:
Staying Secure
Staying on top of WordPress security can feel overwhelming for small business owners without dedicated IT staff. At Your WP Guy, we exist to shoulder that burden for you. Our WordPress experts can fully audit, secure, maintain and support your site - so you can focus on growing your business with peace of mind.
Don't tackle security risks alone. Let us help you assess any impact from this vulnerability, update your plugins, and implement ongoing maintenance to avoid future threats. We treat your website like it's our own - because we know how critical it is for reaching your customers.
Get in touch for a free consultation today on making WordPress security stress-free. Call 678-995-5169 or book a call here. Our knowledgeable team is ready to help you safeguard your online presence.