WordPress CF7 WOW Styler Plugin Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing arbitrary shortcode execution has been identified in the CF7 WOW Styler plugin for WordPress, affecting all versions through 1.7.0. The issue arises because the plugin does not properly validate user input before executing shortcodes, enabling unauthenticated attackers to execute arbitrary shortcodes. Additionally, this vulnerability is susceptible to reflected cross-site scripting. While version 1.7.0 addressed the reflected XSS issue, the arbitrary shortcode execution vulnerability persists.
Impact
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to execute potentially harmful actions or scripts within the WordPress environment. This vulnerability also allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, an unauthenticated user can send a request to a WordPress site with the CF7 WOW Styler plugin installed. The request must include a parameter that the plugin will process without proper validation. This can be done by manipulating the 'cf7cstmzr-form' query variable to include a shortcode that the user wants to execute. Once the request is sent, the injected shortcode will be executed on the site, demonstrating the vulnerability.
Remediation
Users can update to CF7 WOW Styler version 1.7.0 or later, which addresses the reflected cross-site scripting vulnerability, but note that the arbitrary shortcode execution issue remains. For complete protection, users should consider disabling the plugin until a version that fully addresses this vulnerability is available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
