{"id":19018763,"date":"2026-09-13T07:53:36","date_gmt":"2026-09-13T07:53:36","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19018763"},"modified":"2026-09-13T10:10:32","modified_gmt":"2026-09-13T10:10:32","slug":"security-issue-rogue-admin-creation-via-this-plugin","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/security-issue-rogue-admin-creation-via-this-plugin\/","title":{"rendered":"Security Issue: Rogue admin creation via this plugin"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I&#8217;m opening this as its own topic per the forum guidelines, since the existing security thread (&#8220;Security Issue&#8221;, post-202) isn&#8217;t the right place for replies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I manage a WordPress site that was compromised through this exact vulnerability a few days ago, and at least one other site owner has independently reported the same thing (their reply in the other thread was also removed for the same reason &#8211; wrong place to post it, not because the report was wrong).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What happened on our site:<\/p>\n\n\n\n<ul>\n<li>A rogue administrator account was created every time we logged into wp-admin, regardless of password changes.<\/li>\n\n\n\n<li>We traced it to the strcpv_visits_by_page option. One stored &#8220;page name&#8221; contained a single quote followed by an autofocus attribute and an onfocus handler (no literal &lt; character, so it passes through sanitize_text_field() untouched).<\/li>\n\n\n\n<li>That value is written unescaped into HTML attributes in the dashboard widget (class-dashboard-widget.php, get_data_values()), e.g. data-StrCPV-page-name='&#8221; . $key . &#8220;&#8216; and a checkbox value built with json_encode() (which also doesn&#8217;t escape single quotes).<\/li>\n\n\n\n<li>Because of autofocus, the browser focuses the injected element automatically when an admin opens the Dashboard &#8211; no click needed &#8211; and onfocus fires, loading an external script that silently created the new admin account using our own authenticated session.<\/li>\n\n\n\n<li>The page name\/title is taken directly from a $_POST field on the public admin-ajax.php action used for visit counting, so no login or real page visit is required to store it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This matches Patchstack&#8217;s CVE-2026-81795 (CVSS 7.1). Given it&#8217;s already being actively exploited against multiple sites, I&#8217;d suggest treating this as a confirmed vulnerability rather than a scanner false positive, and recommending users deactivate the plugin (or at least the dashboard widget) until a real fix with proper esc_attr()\/esc_html() escaping is released and verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Happy to answer questions or share more detail if useful for reproducing\/fixing this.<\/p>\n","protected":false},"template":"","class_list":["post-19018763","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19018763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19018763\/revisions"}],"predecessor-version":[{"id":19018816,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19018763\/revisions\/19018816"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19018763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}