SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14028

This allows for PHP files to be uploaded.

HIGH 7.2EPSS 15.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content/plugins directory permissions were set up to block all new plugins.

CVSS 3.0
7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
15.23% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
wordpress/wordpress
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.