Another reason to leave WordPress behind
So today it was fires both at work and privately :
I successfully intercepted what appears to have been an attempt to compromise chardonsbleus.org.
Two administrator accounts were created within a very short period of time. At first, I assumed the usual suspects: an outdated WordPress plugin, WPML, or some other vulnerable component.
But that doesn’t appear to be what happened.
The traces left in the logs and database indicate that both administrator accounts were created through a backend API request with administrative privileges. Everything I have found so far points toward the WPMU DEV API key as the attack vector.
What surprised me most is that I had no idea credentials associated with that service could potentially be used in a way that results in the creation of WordPress administrator accounts — apparently without needing the password of an existing administrator.
There is still another possibility: that my main administrator account itself was compromised. It uses a strong password, though, and based on the traces I have, I consider that considerably less likely.
So I’m not claiming to have reconstructed every step of the attack yet. What I do know is that two unauthorized administrator accounts appeared, and the database and logs point to an API-level administrative operation rather than a normal WordPress login.
I don’t know how many people will ever read this, but for me the conclusion is becoming increasingly obvious:
WordPress has to go.
The main reason chardonsbleus.org is still running WordPress is GiveWP. It is a genuinely good donation plugin, although an expensive one, and replacing that functionality has always been the main obstacle to migrating the site.
I’m going to find another solution for donations.
After that, I’ll probably move the site to Indiekit and finally decommission the WordPress installation altogether.
Comments
Sign in with your website to comment:
Loading comments...
No comments yet. Be the first to share your thoughts!