🔙 목록으로 돌아가기

CVE-2020-36719: ListingPro < 2.6.1 - Arbitrary Plugin Installation/Activation/Deactivation

TitleListingPro < 2.6.1 - Arbitrary Plugin Installation/Activation/Deactivation
Authorritikchaddha
SeverityCritical
ImpactUnauthenticated attackers can arbitrarily install, activate or deactivate plugins, potentially installing malicious plugins to gain complete site control.
RemediationUpgrade to ListingPro version 2.6.1 or later.
CVSS Score9.8
EPSS Score0.62965
CVE IDCVE-2020-36719
CWE IDCWE-862
Fofa Querybody="/wp-content/plugins/listingpro"
Tags cve cve2020 wp wp-pluginwordpress listingpro passive vkev vuln

🔍 Vulnerability Description

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.

🌐 HTTP Request

GET /wp-content/themes/listingpro/style.css HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36719.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-36719.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A