Skip to main content

Popular WordPress Plugin Exposes Database to Attack

The popular WordPress plugin NextGEN Gallery (downloaded 16.5 million times) has been found to include a serious SQL injection vulnerability.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The popular WordPress plugin NextGEN Gallery (downloaded 16.5 million times) has been found to include a serious SQL injection vulnerability.

Threat details

This could lead to ransom attacks against the sites data as well as data leaks.

To exploit a site, one of two scenarios must be available to an attacker. The first would require an authenticated user account to exploit the tag gallery short code to inject the exploit. The second requires a NextGEN Basic TagCloud gallery to be used on the site allowing an unauthenticated remote user to inject the exploit using a slightly modified gallery URL.

The latest version of NextGEN Gallery plugin is free from this vulnerability.

Further Technical details:
The vulnerability discovered is a SQL injection type where user input is not correctly sanitised specifically for $container_ids which is created from the tag input.

PHP vsprintf function is used to pass the statement as a format string and the input is passed as value arguments, which are used to sanitise the input removing the immediate danger of a SQL injection. However, the tag input is passed directly into the format string allowing sprintf/printf directives to be passed.

With no sanitation against these directives, the intended action can be controlled. This vulnerability comes into play during the WordPress database abstraction prepare() method where changes are performed on the SQL code. An apostrophe is added after any %s string it finds and passes it through the vsprintf, processing any format strings injected. If carefully crafted, it can be used to alter the SQL query return causing united queries to be run on the backend database that can include sensitive user data.


Remediation steps

Type Step
  • Update the NextGEN Gallery plugin to version 2.1.79 or higher
  • Where possible disable all non-essential plugins to aid in reducing the potential attack surface.
  • Keep WordPress and all plugins up to date with the latest security patches.
  • Ensure all privileged data held within the database is encrypted using a strong hashing algorithm and randomly generated salt where appropriate.

Last edited: 17 February 2020 11:37 am