Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
63Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 9.8epss 7.7%
da publicação à arma50 dias
Publicada no NVD9 de abr.
1ª PoC+50d
probabilidade de exploração
7.7%top 6% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
davidfcarr · Quick PlaygroundPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/52596não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://plugins.trac.wordpress.org/browser/quick-playground/trunk/api.php#L39https://plugins.trac.wordpress.org/browser/quick-playground/trunk/expro-api.php#L419https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3500839%40quick-playground&new=3500839%40quick-playground&sfp_email=&sfph_mail=https://www.wordfence.com/threat-intel/vulnerabilities/id/308cd28a-a477-4bc6-a392-ad5a9eca1cb5?source=cve