PT-2023-18541 · WordPress · Wpforo Forum
Hamed
·
Published
2023-06-09
·
Updated
2023-07-22
·
CVE-2023-2249
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpForo Forum plugin for WordPress versions up to, and including, 2.1.7
Description
The issue is due to the insecure use of
file get contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.Recommendations
For versions up to, and including, 2.1.7, update to a version higher than 2.1.7 to resolve the issue. As a temporary workaround, consider disabling the use of
file get contents until a patch is available. Restrict access to sensitive files like wp-config.php to minimize the risk of exploitation. Avoid using the file get contents function with unverified input until the issue is resolved.Exploit
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wpforo Forum