This article is about how a WordPress Editor can use unfiltered HTML and a some social engineering to gain administrative access to the WordPress site and pwn the server.
Next, I wanted to look at the capabilities that administrators have, that editors do not have. It is clearly listed in WordPress’s Roles and Capabilities page. Two major administrative capabilities are adding or removing users and installing plugins. By installing plugins, administrators can essentially execute PHP code in the server.
Proof of Concept
- Adds a new administrator with the credentials backdoor:pwned
- Installs “Mortgage Calculator Plus” plugin
- Edits the plugin’s source to add a simple PHP code that takes value from the parameter
cmd, execute the commands on the server, and prints the output.
WordPress needs a valid wpnonce value to be sent along with the requests. So in my exploit, I fetched the wpnonce value for each of the above actions from the DOM.
You can download my exploit here.
Now as an attacker, I want the administrator to open this page. Here comes the social engineering part. I send the administrator the following message.
“Hey, I just made an important edit to a page in the website. I’ve sent you the preview link. Please take a look“
The administrator opens the preview link and the code gets executed. Now, I can login as an administrator with the backdoor account.
I can execute commands on the web server using this URL
I reported this to WordPress. And their response is that there cannot be malicious editors because they are supposed to be trusted users in the first place. They also said that WordPress roles are not hierarchical. Administrators are not “greater than” editors, hence there is no “escalation” from editor to administrator.
In their Roles and Capabilities guide, it is shown that editors do not have the capabilities of administrators and super admins. Also they have not mentioned that the editors are equivalent to administrators in terms of trust and privileges.
I personally know 2 people who work as editors in companies which run blogs. Their job is to edit the articles that authors are submitting and send preview links to the administrator before publishing, if it’s an important article. While the companies trust them as editors, they definitely would not want to give them administrative access. I’m sure that there are lots of editors who work like this out there. I explained this to WordPress but they insisted that it is the fault of the operator to add editors who are not trusted enough to be administrators.
My suggestion to WordPress is to disable unfiltered HTML capability for the editors, by default. The administrator can enable it for editors if needed. That way, the administrator will be aware of the risks associated with adding a new editor.
Since WordPress did not accept this as a risk, I do not think they will try to fix it. So, it is advised to not add editors, who you would not add as administrators.