Lucene search

K
wpvulndbUnlock SecurityWPVDB-ID:48820F1D-45CB-4F1F-990D-D132BFC5536F
HistoryNov 21, 2023 - 12:00 a.m.

WP All Export (Free < 1.4.0, Pro < 1.8.6) - Admin+ RCE

2023-11-2100:00:00
Unlock Security
wpscan.com
16
plugin vulnerability
remote code execution
wp all export
security issue
arbitrary command

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

19.3%

Description The plugin does not validate and sanitise the wp_query parameter which allows an attacker to run arbitrary command on the remote server

PoC

1. Go to “All Export” > “New Export” 2. Select “WP Query Results” as the export type 3. Enter the payload phpinfo() for the query. 4. Click customize and see the execution of phpinfo() when the page loads.

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for WPVDB-ID:48820F1D-45CB-4F1F-990D-D132BFC5536F