{"id":160692,"date":"2024-05-20T10:33:06","date_gmt":"2024-05-20T09:33:06","guid":{"rendered":"https:\/\/getshieldsecurity.com\/?p=160692"},"modified":"2024-05-20T10:33:07","modified_gmt":"2024-05-20T09:33:07","slug":"shieldnotes-ep14","status":"publish","type":"post","link":"https:\/\/getshieldsecurity.com\/blog\/shieldnotes-ep14\/","title":{"rendered":"ShieldNOTES Ep#14: ACF &amp; JetPack Vulnerabilities, Japanese Keyword Hack from our Blog, &amp; SSH Security"},"content":{"rendered":"\n<p>There are many new vulnerabilities out there this week, including JetPack and Advanced Custom Fields.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#1 &#8211; Vulnerable: Advanced Custom Field PRO<\/h2>\n\n\n\n<p>With 2+ million installations for the free version, many will be running the Pro edition.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>Upgrade ASAP to v6.2.10+<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>Severity risk 9.9\/10 &#8211; risk of local file inclusion!<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/advanced-custom-fields-pro\/wordpress-advanced-custom-fields-pro-plugin-6-2-10-contributor-local-file-inclusion-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#2 &#8211; Vulnerable: Elementor \u2013 Header, Footer &amp; Blocks Templates<\/h2>\n\n\n\n<p>1+ million installations so many Elementor fans will be using this.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>Upgrade ASAP to v 1.6.29+<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>XSS allowing injection of malicious scripts into website that guests may execute.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/header-footer-elementor\/wordpress-elementor-header-footer-builder-plugin-1-6-28-authenticated-contributor-stored-cross-site-scripting-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#3 &#8211; Vulnerable: JetPack<\/h2>\n\n\n\n<p>Not the most severe, but huge installation base.<\/p>\n\n\n\n<p><strong>How will I know I&#8217;m okay?<\/strong><br>Upgrade ASAP to v 13.3.1+<\/p>\n\n\n\n<p><strong>What&#8217;s the risk?<\/strong><br>XSS allowing injection of malicious scripts into website that guests may execute.<\/p>\n\n\n\n<p><strong>Editor Comment<\/strong><br>Please use <a href=\"https:\/\/getshieldsecurity.com\/blog\/wordpress-plugin-vulnerability-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">ShieldPRO&#8217;s auto-upgrade feature<\/a> for vulnerable plugins.<\/p>\n\n\n\n<p><a href=\"https:\/\/patchstack.com\/database\/vulnerability\/jetpack\/wordpress-jetpack-plugin-13-3-1-authenticated-contributor-stored-cross-site-scripting-via-wpvideo-shortcode-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#4 &#8211; From our blog: Japanese Keyword Hack Primer<\/h2>\n\n\n\n<p>This article outlines the principles of the Japanese keyword hack and how you might spot it, and mitigate it.<\/p>\n\n\n\n<p><a href=\"https:\/\/getshieldsecurity.com\/blog\/japanese-keyword-hack\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">#5 &#8211; Server Root SSH Access For Sale<\/h2>\n\n\n\n<p>This article demonstrates that security at all levels of your WordPress infrastructure is critical. If you regularly access your server over SSH, make sure you&#8217;re not re-using passwords, and you&#8217;re using the latest versions of your SSH client.<\/p>\n\n\n\n<p><strong>Keys &amp; Certificates over Passwords<\/strong><br>If you&#8217;re using passwords to access your servers via SSH, consider switching to Public\/Private Keys, or even Certificates &#8211; far more secure and versatile.<\/p>\n\n\n\n<p><a href=\"https:\/\/cybersecuritynews.com\/root-access-shh-accounts-hacker-forums\/\" target=\"_blank\" rel=\"noreferrer noopener\">More Info \u2192<\/a><\/p>\n\n\n\n<p>Thanks for reading, and have a great week!<\/p>\n\n\n\n<p><strong>Paul Goodchild<\/strong><br><em>Shield Security for WordPress<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are many new vulnerabilities out there this week, including JetPack and Advanced Custom Fields.<\/p>\n","protected":false},"author":27,"featured_media":157238,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,153,201],"tags":[69],"class_list":["post-160692","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-security-wordpress-solutions","category-shieldnotes","tag-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/160692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/comments?post=160692"}],"version-history":[{"count":2,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/160692\/revisions"}],"predecessor-version":[{"id":160694,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/posts\/160692\/revisions\/160694"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media\/157238"}],"wp:attachment":[{"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/media?parent=160692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/categories?post=160692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/getshieldsecurity.com\/wp-json\/wp\/v2\/tags?post=160692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}