Thanh Toán Quét Mã QR Code Tự Động Stored Cross-Site Scripting Vulnerability (CVE-2024-8914) — High Severity

Understanding the Risk: Stored Cross-Site Scripting in WordPress QR Code Plugin

A significant security flaw, identified as CVE-2024-8914, has been discovered in the “Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam” plugin for WordPress. This vulnerability, categorized as Stored Cross-Site Scripting (XSS), poses a high risk to websites using the affected plugin. It could allow malicious actors to inject harmful code into your website, which then executes in the browsers of unsuspecting users visiting the compromised pages.

This type of attack is particularly dangerous because the malicious script is stored directly on the vulnerable server. When a user visits a page containing this script, their browser executes it without realizing it’s from an untrusted source. This can lead to various problems, including stealing user session cookies, redirecting users to malicious websites, or defacing the website.

CVE Details

  • Product: Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress
  • Published Date: September 25, 2024
  • Severity: High
  • Status: Analyzed

Affected Products

The Stored Cross-Site Scripting (XSS) vulnerability affects all versions of the “Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam” plugin for WordPress up to, and including, version 2.0.1.

Current Status

The vulnerability has been thoroughly analyzed and publicly disclosed. Users running the affected plugin versions are at risk. It is critical for website administrators and developers to take immediate action to protect their sites.

Severity Level

This vulnerability is rated as High Severity, with a CVSS (Common Vulnerability Scoring System) score of 7.2. A high severity rating indicates that the flaw can be easily exploited and could lead to significant impact on the confidentiality, integrity, or availability of your website and user data.

Possible Solutions

To secure your WordPress website from this XSS vulnerability, the primary course of action is to update your “Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam” plugin to a version greater than 2.0.1 as soon as an official patch is released by the developer. Always back up your website before performing any updates.

The root cause of this vulnerability lies in the plugin’s improper use of the wp_kses_allowed_html function, which incorrectly allowed the onclick attribute for certain HTML elements. While awaiting an official update, you should:

  1. Monitor for Updates: Regularly check the official WordPress plugin repository page for “Thanh Toán Quét Mã QR Code Tự Động” for new versions that address this flaw.
  2. Web Application Firewall (WAF): Employ a robust WAF solution. A WAF can help mitigate XSS attacks by filtering out malicious input before it reaches your application and blocking suspicious requests.
  3. Temporarily Deactivate: If updating is not immediately possible and your website can function without this plugin, consider deactivating it temporarily until a secure version is available.

References

https://plugins.trac.wordpress.org/browser/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/trunk/inc/functions.php#L184
https://wordpress.org/plugins/bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/#developers
https://www.wordfence.com/threat-intel/vulnerabilities/id/8ef7c48b-e8f2-40bd-aa48-191059e15453?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.