﻿{"id":676,"date":"2020-02-18T12:47:36","date_gmt":"2020-02-18T18:47:36","guid":{"rendered":"https:\/\/www.uv.mx\/csirt\/?p=676"},"modified":"2020-03-02T12:53:22","modified_gmt":"2020-03-02T18:53:22","slug":"18-02-2020-vulnerabilidad-en-plugin-de-wordpress","status":"publish","type":"post","link":"https:\/\/www.uv.mx\/csirt\/boletines\/vulnerabilidades\/18-02-2020-vulnerabilidad-en-plugin-de-wordpress\/","title":{"rendered":"18\/02\/2020 \u00a0Vulnerabilidad en plugin de WordPress"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div style=\"width: 752px;max-width: 752px;height: auto;border: 1px solid #369;margin: 0px auto;background-color: #fff\">\n<p><img decoding=\"async\" style=\"width: 750px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/boletin-encabezado.jpg\" alt=\"\" \/><\/p>\n<table style=\"width: 100%\" border=\"0\" cellspacing=\"1\" cellpadding=\"1\" align=\"center\">\n<tbody>\n<tr>\n<td><img decoding=\"async\" style=\"width: 190px;height: 25px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_importante.jpg\" alt=\"\" \/><\/td>\n<td style=\"text-align: right\"><span style=\"font-size: 18px\"><span style=\"color: #666666\"><span style=\"font-family: tahoma,geneva,sans-serif\">18 de febrero de 2020<\/span><\/span><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><strong>\u00a0Vulnerabilidad en plugin de WordPress<\/strong><\/div>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><span style=\"font-size: 16px\">ID: 18022005<\/span><\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Descripci\u00f3n<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">A trav\u00e9s\u00a0de un informe de la empresa de seguridad WebARX se ha dado a conocer una vulnerabilidad en un plugin de temas\u00a0\u00ab<strong>ThemeGrill Demo Importer<\/strong>\u00bb que viene incluido gratuitamente as\u00ed como en versi\u00f3n premium, contando con m\u00e1s de 200,000 instalaciones activas.<\/p>\n<p style=\"text-align: justify\">Cuando se instala y activa un tema de <em>ThemeGrill<\/em>, el complemento ejecuta algunas funciones con privilegios administrativos sin verificar previamente si el usuario que ejecuta el c\u00f3digo est\u00e1 autenticado y si es administrador, esto podr\u00eda permitir que un atacante remoto no autenticado pueda borrar\u00a0 toda la base de datos de sitios web espec\u00edficos.<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><strong><span style=\"font-size: 16px\">Productos afectados<\/span><\/strong><\/span><\/p>\n<\/div>\n<div style=\"background-color: #f7931e;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<ul>\n<li>ThemeGrill Demo Importer v.1.3.4 y v.1.6.1<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Soluci\u00f3n:<\/strong><\/span><\/span><\/p>\n<p>En la p\u00e1gina de webARX se ha puesto un enlace que apunta un blog deWordPress <a href=\"https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=2245070%40themegrill-demo-importer%2Ftrunk&amp;old=2190304%40themegrill-demo-importer%2Ftrunk&amp;sfp_email=&amp;sfph_mail=\">https:\/\/plugins.trac.wordpress.org\/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=2245070%40themegrill-demo-importer%2Ftrunk&amp;old=2190304%40themegrill-demo-importer%2Ftrunk&amp;sfp_email=&amp;sfph_mail=<\/a> d\u00f3nde se explica la manera de crear una regla especial para bloquear esta vulnerabilidad.<\/p>\n<p>Para m\u00e1s informaci\u00f3n:<\/p>\n<p><a href=\"https:\/\/www.webarxsecurity.com\/critical-issue-in-themegrill-demo-importer\/\">https:\/\/www.webarxsecurity.com\/critical-issue-in-themegrill-demo-importer\/<\/a><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<p><img decoding=\"async\" style=\"width: 750px;height: 120px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_inferior.jpg\" alt=\"\" \/><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; 18 de febrero de 2020 \u00a0Vulnerabilidad en plugin de WordPress ID: 18022005 Descripci\u00f3n A trav\u00e9s\u00a0de un informe de la empresa de seguridad WebARX se ha dado a conocer una vulnerabilidad en un plugin de temas\u00a0\u00abThemeGrill Demo Importer\u00bb que viene incluido gratuitamente as\u00ed como en versi\u00f3n premium, contando con m\u00e1s de 200,000 instalaciones activas. Cuando [&hellip;]<\/p>\n","protected":false},"author":2037,"featured_media":465,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ventana_nueva":"","tipo_url":"","url":"","extracto":"","imagen_halign":"","imagen_valign":"","bg_size":"","text_hide":"","media_url":"","tipo_media":"","video_url":"","video_pos":"","video_youtube":"","footnotes":""},"categories":[16,15],"tags":[],"class_list":["post-676","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-importantes","category-vulnerabilidades"],"_links":{"self":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/676","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/users\/2037"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/comments?post=676"}],"version-history":[{"count":0,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/676\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media\/465"}],"wp:attachment":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media?parent=676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/categories?post=676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/tags?post=676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}