PT-2024-17362 · WordPress · Classic Addons – Wpbakery Page Builder
Nir Kum
+2
·
Published
2024-12-04
·
Updated
2024-12-09
·
CVE-2024-11952
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Classic Addons – WPBakery Page Builder plugin for WordPress versions up to, and including, 3.0
Description
The issue allows authenticated attackers with Contributor-level access and above, and permissions granted by an Administrator, to include and execute arbitrary PHP files on the server via the
style parameter. This enables the execution of any PHP code in those files, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The issue is limited to PHP files in a Windows environment.Recommendations
For Classic Addons – WPBakery Page Builder plugin for WordPress versions up to, and including, 3.0, consider disabling the
style parameter to prevent the inclusion and execution of arbitrary PHP files until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially for users with Contributor-level access and above.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Classic Addons – Wpbakery Page Builder