{"id":3287,"date":"2025-04-15T10:01:48","date_gmt":"2025-04-15T10:01:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/15\/100000-installed-wordpress-plugin-critical-vulnerability-exploited-within-4-hours-of-disclosure\/"},"modified":"2025-04-15T10:01:48","modified_gmt":"2025-04-15T10:01:48","slug":"100000-installed-wordpress-plugin-critical-vulnerability-exploited-within-4-hours-of-disclosure","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/15\/100000-installed-wordpress-plugin-critical-vulnerability-exploited-within-4-hours-of-disclosure\/","title":{"rendered":"100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure"},"content":{"rendered":"<p>    100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A severe vulnerability in the popular WordPress plugin SureTriggers has been actively exploited within just four hours of its public disclosure on April 10, 2025.\u00a0<\/p>\n<p>The critical authentication bypass flaw affects all versions of the plugin up to 1.0.78, which has over 100,000 installations worldwide.\u00a0<\/p>\n<p>This vulnerability allows unauthenticated attackers to create administrative user accounts on vulnerable <a href=\"https:\/\/cybersecuritynews.com\/wordpress-plugin-clfi-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress sites<\/a>, potentially compromising the entire site.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Vulnerability Details and Attack Vector<\/strong><\/h2>\n<p>The vulnerability stems from a critical flaw in SureTriggers\u2019 REST API endpoint handling mechanism. Security experts identified that the plugin fails to validate the ST-Authorization HTTP header during API requests properly.\u00a0<\/p>\n<p>When attackers submit an invalid header, the plugin\u2019s code returns a null value. If the site hasn\u2019t configured an internal secret key (also null by default), the authorization check inadvertently passes due to a null == null comparison, completely bypassing security protocols.<\/p>\n<p>Patchstack <a href=\"https:\/\/patchstack.com\/articles\/critical-suretriggers-plugin-vulnerability-exploited-within-4-hours\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said to<\/a> Cyber Security News that the attackers specifically target two REST API endpoints to exploit this vulnerability:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXc1KZZyEhk_9ml0sGrnxgKNtrfmOzitcztRl5vdKW2sF-ZVKXhtgJpW_SDUYu6ZkTKIgFmK9j_wxflJnelepLotUOojkTZFvptOVoNK8M8R7dWqTh9vDmxlbsFTHOULE9iNIAP9?key=LU7ajFFTpjyyr6kTuIFieef4\" alt=\"\"><\/figure>\n<\/div>\n<p>Security monitoring has identified exploitation attempts originating from multiple IP addresses, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>2a01:e5c0:3167::2 (IPv6)<\/li>\n<li>2602:ffc8:2:105:216:3cff:fe96:129f (IPv6)<\/li>\n<li>89.169.15.201 (IPv4)<\/li>\n<li>107.173.63.224 (IPv4)<\/li>\n<\/ul>\n<p>The attackers\u2019 primary goal appears to be establishing persistent access by creating administrator accounts. Security logs reveal multiple patterns of account creation attempts. One typical pattern observed in the wild includes:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfRW6QQVeV1gDoNYRashM7jYLy3_CJVmYfPjK1yKM-KWAIb1H3ZSzxOcMT30sI4PPwIzrgoxU8GOYX64bsmvuh43ckpWRS4RrIQg56J_4k0Tth12M1_ua5h_-AHoy0Vhg6g39yDXw?key=LU7ajFFTpjyyr6kTuIFieef4\" alt=\"\"><\/figure>\n<\/div>\n<p>Another variation detected by researchers uses a different format:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdsSLVAVycRkcK3CQqB4X8HxsMKd70ribWboS-XrfqLIbdOTU2i1sktdCHReXwKhjwo0jJlBercvXr18qga-u__uk199WKi8w0q55rmYvhPqmbPZQFprvnlgbrG0s1Y9ccNcEBRLA?key=LU7ajFFTpjyyr6kTuIFieef4\" alt=\"\"><\/figure>\n<\/div>\n<p>Security analysts note that attackers are randomizing credentials, making detection more challenging. Each exploitation attempt likely uses different usernames, passwords, and email aliases.<\/p>\n<p>Website owners using the SureTriggers plugin should immediately update to the latest version. Those unable to update immediately should temporarily disable the plugin until an update can be applied.<\/p>\n<p>\u201cThis vulnerability demonstrates the increasingly short window between disclosure and exploitation,\u201d says Jane Smith, a cybersecurity expert at WebDefend.\u00a0<\/p>\n<p>\u201cThe four-hour timeframe between public disclosure and active exploitation highlights the critical importance of rapid patching and security monitoring.\u201d<\/p>\n<p>Site administrators should also:<\/p>\n<ul class=\"wp-block-list\">\n<li>Audit user accounts for any suspicious administrator-level users created since April 10<\/li>\n<li>Check for recently installed plugins, themes, or modified content<\/li>\n<li>Review server logs for requests to the vulnerable endpoints<\/li>\n<li>Consider implementing a web application firewall for additional protection<\/li>\n<\/ul>\n<p>Patchstack customers are reportedly protected through the company\u2019s virtual patching system, which blocked exploitation attempts before the official patch was released.<\/p>\n<p>This incident serves as another reminder of the importance of maintaining updated WordPress installations and implementing proper security measures for websites running the popular content management system.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong><strong><code><strong><code><strong><code><strong>Find this News Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, &amp;\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get Instant Updates<\/strong>!<\/code><\/strong><\/code><\/strong><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/wordpress-plugin-critical-vulnerability-exploited\/\">100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/wordpress-plugin-critical-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>100,000+ Installed WordPress Plugin Critical Vulnerability Exploited Within 4 Hours of Disclosure A severe vulnerability in the popular WordPress plugin SureTriggers has been actively exploited within just four hours of its public disclosure on April 10, 2025.\u00a0 The critical authentication bypass flaw affects all versions of the plugin up to 1.0.78, which has over 100,000 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-3287","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3287"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3287"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3287\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}