PT-2023-32349 · WordPress · The News & Blog Designer Pack
Florian Hauser
·
Publicado
2023-10-27
·
Atualizado
2025-12-02
·
CVE-2023-5815
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The News & Blog Designer Pack – WordPress Blog Plugin versions up to, and including, 3.4.1
Description
The issue is related to Remote Code Execution via Local File Inclusion. This is due to the
bdp get more post function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code execution. On vulnerable Docker configurations, it may be possible for an attacker to create a PHP file and then subsequently include it to achieve RCE. Approximately 30,000 sites are at risk.Recommendations
For versions up to, and including, 3.4.1, update to a version that fixes the
bdp get more post function to prevent the use of the unsafe extract() method. As a temporary workaround, consider disabling the bdp get more post function hooked via a nopriv AJAX until a patch is available. Restrict access to the include() function to minimize the risk of exploitation. Avoid using the POST variable in the affected AJAX endpoint until the issue is resolved.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
The News & Blog Designer Pack