Lucene search

K
wpvulndbApple502jWPVDB-ID:47652B24-A6F0-4BBC-834E-496B88523FE7
HistoryFeb 01, 2022 - 12:00 a.m.

Cost Calculator <= 1.8 - Authenticated Local File Inclusion

2022-02-0100:00:00
apple502j
wpscan.com
9
cost calculator
authenticated users
path traversal
local file inclusion
windows web servers
admin+

EPSS

0.001

Percentile

40.2%

The plugin allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.8) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post’s Layout

PoC

As a contributor, create a Cost Calculator post, set the Layout to /…/…/…/…/…/…/…/…/…/…/file (assuming the file to include is at C:\xampp\file.php and WordPress is installed at C:\xampp\htdocs\wordpress). Save as draft, then embde the calculator using the related shortcode (e.g [nd_cost_calculator id=“806”]) and preview the post to trigger the LFI.

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:47652B24-A6F0-4BBC-834E-496B88523FE7