🔙 목록으로 돌아가기

CVE-2019-6703: Total Donations Plugin for WordPress < 2.0.6 - Arbitrary Options Update

TitleTotal Donations Plugin for WordPress < 2.0.6 - Arbitrary Options Update
AuthorDhiyaneshDK
SeverityCritical
ImpactAttackers can modify site options, enabling new user registration as Administrator, leading to site takeover.
RemediationUpdate to the latest version of the plugin where this issue is fixed.
CVSS Score9.8
EPSS Score0.54383
CVE IDCVE-2019-6703
Fofa Querybody="/wp-content/plugins/total-donations/"
Tags cve cve2019 wpscan wordpress wp wp-plugin total-donations passive vkev vuln

🔍 Vulnerability Description

Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

🌐 HTTP Request

GET /wp-content/plugins/total-donations/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_6; en-en) AppleWebKit/533.19.4 (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-6703.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-6703.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A