PT-2018-12284 · WordPress+1 · Wordpress+1
Viniciusmarangoni
·
Published
2018-08-10
·
Updated
2018-10-10
·
CVE-2018-14028
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress version 4.9.7
Description
The issue allows for the upload of PHP files via the admin area without proper verification as ZIP files. Once uploaded, even though the plugin extraction fails, the PHP file remains in a predictable location within
wp-content/uploads, enabling an attacker to execute the file. This poses a security risk, particularly in scenarios where an attacker cannot upload arbitrary PHP code into a valid plugin ZIP file due to restricted permissions in the wp-content/plugins directory.Recommendations
For WordPress version 4.9.7, update to a version that includes the fix for this issue to prevent the upload and execution of unauthorized PHP files.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Wordpress