An authenticated settings change vulnerability in the YIT Plugin Framework, used in several dozen WordPress plugins, could allow logged-in users to change the plugin options.
Reference
CVE-2019-16251
Summary
The YIT Plugin Framework is used in most plugins from YITH hosted on wordpress.org, as well as in their premium plugins. The framework version 3.3.8 and below was prone to two vulnerabilities:
- An authenticated settings change vulnerability could allow logged-in users to modify the plugin options. This issue affects several dozen plugins (see the list below).
- A vulnerability could allow logged-in users to insert or update custom post types. Although this vulnerable code is included in the framework, it does not seem to be used by any of the free plugins available in the wordpress.org repo.
Below is a list of plugins that are or aren’t vulnerable. Note that this is a non-exhaustive list because it covers only the 60 plugins available on wordpress.org, not the premium plugins that are available on YITH website.
The following 38 plugins are vulnerable to the authenticated settings change vulnerability:
- yith-woocommerce-wishlist <=2.2.13 (700,000+ installations).
- yith-woocommerce-compare <=2.3.13 (200,000+ installations).
- yith-woocommerce-quick-view <=1.3.13 (100,000+ installations).
- yith-woocommerce-zoom-magnifier <=1.3.11 (80,000+ installations).
- yith-woocommerce-ajax-search <=1.6.9 (80,000+ installations).
- yith-woocommerce-badges-management <=1.3.19 (10,000+ installations).
- yith-woocommerce-brands-add-on <=1.3.6 (10,000+ installations).
- yith-woocommerce-request-a-quote <=1.4.7 (10,000+ installations).
- yith-woocommerce-social-login <=1.3.4 (10,000+ installations).
- yith-woocommerce-order-tracking <=1.2.10 (9,000+ installations).
- yith-woocommerce-pdf-invoice <=1.2.12 (7,000+ installations).
- yith-pre-order-for-woocommerce <=1.1.9 (7,000+ installations).
- yith-woocommerce-advanced-reviews <=1.3.9 (6,000+ installations).
- yith-woocommerce-product-add-ons <=1.5.21 (7,000+ installations).
- yith-woocommerce-gift-cards <=1.3.7 (5,000+ installations).
- yith-woocommerce-subscription <=1.3.4 (6,000+ installations).
- yith-woocommerce-affiliates <=1.6.3 (5,000+ installations).
- yith-woocommerce-cart-messages <=1.4.3 (4,000+ installations).
- yith-woocommerce-product-bundles <=1.1.15 (4,000+ installations).
- yith-woocommerce-frequently-bought-together <=1.2.10 (4,000+ installations).
- yith-woocommerce-multi-step-checkout <=1.7.4 (3,000+ installations).
- yith-color-and-label-variations-for-woocommerce <=1.8.11 (3,000+ installations).
- yith-custom-thank-you-page-for-woocommerce <=1.1.6 (3,000+ installations).
- yith-product-size-charts-for-woocommerce <=1.1.1 (2,000+ installations).
- yith-woocommerce-added-to-cart-popup <=1.3.11 (2,000+ installations).
- yith-woocommerce-bulk-product-editing <=1.2.13 (2,000+ installations).
- yith-woocommerce-stripe <=2.0.1 (2,000+ installations).
- yith-woocommerce-waiting-list <=1.3.9 (2,000+ installations).
- yith-woocommerce-points-and-rewards <=1.3.4 (2,000+ installations).
- yith-advanced-refund-system-for-woocommerce <=1.0.10 (1,000+ installations).
- yith-woocommerce-authorizenet-payment-gateway <=1.1.12 (1,000+ installations).
- yith-woocommerce-best-sellers <=1.1.11 (1,000+ installations).
- yith-woocommerce-mailchimp <=2.1.3 (1,000+ installations).
- yith-woocommerce-product-vendors <=3.4.0 (1,000+ installations).
- yith-woocommerce-questions-and-answers <=1.1.9 (1,000+ installations).
- yith-woocommerce-recover-abandoned-cart <=1.3.2 (1,000+ installations).
- yith-paypal-express-checkout-for-woocommerce <=1.2.5 (800+ installations).
- yith-desktop-notifications-for-woocommerce <=1.2.7 (500+ installations).
The following 16 plugins include the vulnerable YIT Plugin Framework but aren’t vulnerable to the authenticated settings change vulnerability because they do not use that function. A new version was released and it is recommended to update them:
- yith-woocommerce-ajax-navigation <=3.7.1(100,000+ installations).
- yith-woocommerce-catalog-mode <=1.6.10 (50,000+ installations).
- yith-essential-kit-for-woocommerce-1 <=2.0.8 (10,000+ installations).
- yith-infinite-scrolling <=1.1.8 (10,000+ installations).
- yith-woocommerce-popup <=1.3.3 (8,000+ installations).
- yith-woocommerce-featured-video <=1.2.5 (7,000+ installations).
- yith-woocommerce-tab-manager <=1.2.15 (7,000+ installations).
- yith-woocommerce-category-accordion <=1.0.29 (5,000+ installations).
- yith-woocommerce-name-your-price <=1.1.7 (4,000+ installations).
- yith-woocommerce-product-slider-carousel <=1.10.34 (5,000+ installations).
- yith-woocommerce-dynamic-pricing-and-discounts <=1.3.5 (2,000+ installations).
- yith-woocommerce-review-reminder <=1.5.3 (2,000+ installations).
- yith-live-chat <=1.3.7 (1,000+ installations).
- yith-purchased-column-for-woocommerce <=1.1.4 (1,000+ installations).
- yith-donations-for-woocommerce <=1.1.7 (800+ installations).
- yith-woocommerce-save-for-later <=1.0.18 (300+ installations).
The following – and last – 6 plugins do not include the YIT Plugin Framework and thus aren’t vulnerable:
- yith-custom-login
- yith-footer-banner
- yith-maintenance-mode
- yith-newsletter-popup
- yith-pre-launch
- yith-topbar-countdown
Authenticated settings change
The main vulnerability can be found in the “plugin-fw/lib/yit-plugin-panel-wc.php” script:
add_action( 'admin_action_yith_plugin_fw_save_toggle_element', array( $this, 'save_toggle_element_options' ) );
The framework registers the save_toggle_element_options
function via the admin_action_*
hook which can be triggered by an authenticated user.
public function save_toggle_element_options() { $posted = $_POST; $tabs = $this->get_available_tabs(); $yit_options = $this->get_main_array_options(); $current_tab = isset( $_REQUEST[ 'tab' ] ) && in_array( $_REQUEST[ 'tab' ], $tabs ) ? $_REQUEST[ 'tab' ] : $tabs[ 0 ]; $option_id = isset( $_REQUEST[ 'toggle_id' ] ) ? $_REQUEST[ 'toggle_id' ] : ''; $updated = false; if ( !empty( $yit_options[ $current_tab ] ) && !empty( $option_id ) ) { $tab_options = $yit_options[ $current_tab ]; foreach ( $tab_options as $key => $item ) { if ( !isset( $item[ 'id' ] ) ) { unset( $tab_options[ $key ] ); } } $option_array = array_combine( wp_list_pluck( $tab_options, 'id' ), $tab_options ); if ( isset( $option_array[ $option_id ] ) ) { $value = isset( $posted[ $option_id ] ) ? $posted[ $option_id ] : ''; //drag and drop $order_elements = isset( $posted[ 'yith_toggle_elements_order_keys' ] ) ? explode( ',', $posted[ 'yith_toggle_elements_order_keys' ] ) : false; if ( $order_elements ) { $i = 0; $new_value = array(); foreach ( $order_elements as $key ) { $index = apply_filters( 'yith_toggle_elements_index', $i++, $key ); $new_value[ $index ] = $value[ $key ]; } $value = $new_value; } $value = self::sanitize_option( $value, $option_array[ $option_id ], $value ); $updated = update_option( $option_id, $value ); } } return $updated; }
This function is described as being used to “save the content of the toggle element present inside the panel”, but because it lacks capability check and a security nonce, it can be misused by a logged-in user to change the plugin settings.
Timeline
The vulnerability was discovered and reported to the YITH team on August 12, 2019.
Recommendations
Update any YITH plugin to the latest available version.
If you are using our web application firewall for WordPress, NinjaFirewall WP Edition (free) and NinjaFirewall WP+ Edition (premium), you are protected against this vulnerability.
Stay informed about the latest vulnerabilities in WordPress plugins and themes: @nintechnet