Security Issue: Rogue admin creation via this plugin
-
I’m opening this as its own topic per the forum guidelines, since the existing security thread (“Security Issue”, post-202) isn’t the right place for replies.
I manage a WordPress site that was compromised through this exact vulnerability a few days ago, and at least one other site owner has independently reported the same thing (their reply in the other thread was also removed for the same reason – wrong place to post it, not because the report was wrong).
What happened on our site:
- A rogue administrator account was created every time we logged into wp-admin, regardless of password changes.
- We traced it to the strcpv_visits_by_page option. One stored “page name” contained a single quote followed by an autofocus attribute and an onfocus handler (no literal < character, so it passes through sanitize_text_field() untouched).
- That value is written unescaped into HTML attributes in the dashboard widget (class-dashboard-widget.php, get_data_values()), e.g. data-StrCPV-page-name='” . $key . “‘ and a checkbox value built with json_encode() (which also doesn’t escape single quotes).
- Because of autofocus, the browser focuses the injected element automatically when an admin opens the Dashboard – no click needed – and onfocus fires, loading an external script that silently created the new admin account using our own authenticated session.
- The page name/title is taken directly from a $_POST field on the public admin-ajax.php action used for visit counting, so no login or real page visit is required to store it.
This matches Patchstack’s CVE-2026-81795 (CVSS 7.1). Given it’s already being actively exploited against multiple sites, I’d suggest treating this as a confirmed vulnerability rather than a scanner false positive, and recommending users deactivate the plugin (or at least the dashboard widget) until a real fix with proper esc_attr()/esc_html() escaping is released and verified.
Happy to answer questions or share more detail if useful for reproducing/fixing this.
You must be logged in to reply to this topic.