The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29506 The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:03:46.380Z

Reserved: 2020-02-06T00:00:00

Link: CVE-2020-8658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-06T03:15:10.827

Modified: 2024-11-21T05:39:12.757

Link: CVE-2020-8658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.