CVE-2024-37212
📋 TL;DR
This CSRF vulnerability in Ali2Woo Lite WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions, potentially leading to PHP object injection. It affects all WordPress sites running Ali2Woo Lite version 3.3.5 and earlier.
💻 Affected Systems
- Ali2Woo Lite WordPress Plugin
📦 What is this software?
⚠️ Risk & Real-World Impact
Worst Case
Complete site compromise through PHP object injection leading to remote code execution, data theft, or site defacement
Likely Case
Unauthorized plugin configuration changes, data manipulation, or privilege escalation
If Mitigated
No impact if CSRF protections are properly implemented
🎯 Exploit Status
Exploit requires social engineering to trick admin into clicking malicious link
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: 3.3.6 or later
Restart Required: No
Instructions:
1. Log into WordPress admin panel
2. Go to Plugins → Installed Plugins
3. Find Ali2Woo Lite
4. Click 'Update Now' if available
5. If no update available, deactivate and delete plugin
🔧 Temporary Workarounds
Implement CSRF Protection
allAdd nonce verification to all plugin forms and actions
Disable Plugin
linuxTemporarily deactivate Ali2Woo Lite until patched
wp plugin deactivate ali2woo-lite
🧯 If You Can't Patch
- Restrict admin access to trusted networks only
- Implement web application firewall with CSRF protection rules
🔍 How to Verify
Check if Vulnerable:
Check WordPress admin → Plugins → Ali2Woo Lite version
Check Version:
wp plugin list --name=ali2woo-lite --field=version
Verify Fix Applied:
Verify plugin version is 3.3.6 or higher
📡 Detection & Monitoring
Log Indicators:
- Unusual POST requests to admin-ajax.php with ali2woo parameters
- Multiple failed CSRF token validations
Network Indicators:
- Cross-origin requests to WordPress admin endpoints
- Suspicious referrer headers
SIEM Query:
source="wordpress.log" AND "ali2woo" AND "admin-ajax.php" AND status=200
🔗 References
- https://patchstack.com/database/vulnerability/ali2woo-lite/wordpress-aliexpress-dropshipping-with-alinext-lite-plugin-3-3-5-csrf-to-php-object-injection-vulnerability?_s_id=cve
- https://patchstack.com/database/vulnerability/ali2woo-lite/wordpress-aliexpress-dropshipping-with-alinext-lite-plugin-3-3-5-csrf-to-php-object-injection-vulnerability?_s_id=cve