vulnerability

Wordpress: CVE-2018-14028: Unrestricted Upload of File with Dangerous Type

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
2018-08-10
Added
2018-10-16
Modified
2024-11-27

Description

In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content/plugins directory permissions were set up to block all new plugins.

Solution

misc-no-solution-exists
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.