PT-2024-37086 · WordPress · Wpbakery Visual Composer
João Pedro Soares De Alcântara
·
Published
2024-08-06
·
Updated
2024-08-06
·
CVE-2024-5709
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WPBakery Visual Composer plugin for WordPress versions up to, and including, 7.7
Description:
The issue allows authenticated attackers with Author-level access and above, and with post permissions granted by an Administrator, to include and execute arbitrary files on the server via the
layout name parameter. This enables the execution of any PHP code in those files, which can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.Recommendations:
For versions up to, and including, 7.7, consider disabling the
layout name parameter until a patch is available to prevent the inclusion and execution of arbitrary files. Restrict access to file uploads and execution to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpbakery Visual Composer