WordPress Plugin Vulnerabilities

Business Directory Plugin < 5.11 - Arbitrary File Upload to RCE

Description

The plugin suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.

Note (WPScanTeam): CSRF check and some file validation were added in v5.11, however a blacklist approach was used to forbid specific files (such as php), still allowing php4 to be uploaded by a high privilege user and a separate issue has been created for it

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
0xB9
Submitter
0xB9
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-04-11 (about 4 years ago)
Added
2021-04-12 (about 4 years ago)
Last Updated
2021-04-14 (about 4 years ago)

Other