9.8
CVSSv3

CVE-2020-10564

Published: 13/03/2020 Updated: 19/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the File Upload plugin prior to 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iptanus wordpress file upload

Github Repositories

Vulnerable WordPress Application Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up $ docker-compose down

Vulnerable Wordpress Environment for educational purposes

Vulnerable Wordpress (VWP) This repo is a modified version of the DVWP made by vavkamil - githubcom/vavkamil/dvwp VWP is an intentionally created vulnerable wordpress environment made for vulnerability research, penetration testing practices, and source code review 한글 문서를 보시려면 READMEkomd 를 참고해주세요 Credits As mentioned above, this re

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down

Damn Vulnerable WordPress

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down

Vulnerable WordPress Application Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up $ docker-compose down

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker compose up -d --build $ docker compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down Shell docker exec -ti dvwp-wordpress-1 /bin/bash Interface Loopback IP