7.5
CVSSv2

CVE-2020-10564

Published: 13/03/2020 Updated: 19/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the File Upload plugin prior to 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

iptanus wordpress file upload

Github Repositories

Vulnerable Wordpress Environment for educational purposes

Vulnerable Wordpress (VWP) This repo is a modified version of the DVWP made by vavkamil - githubcom/vavkamil/dvwp VWP is an intentionally created vulnerable wordpress environment made for vulnerability research, penetration testing practices, and source code review 한글 문서를 보시려면 READMEkomd 를 참고해주세요 Credits As mentioned above, this re

Vulnerable WordPress Application Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up $ docker-compose down

Damn Vulnerable WordPress

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down

Vulnerable WordPress Application Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up $ docker-compose down

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker compose up -d --build $ docker compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down Shell docker exec -ti dvwp-wordpress-1 /bin/bash Interface Loopback IP

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down

Damn Vulnerable WordPress Playground for WordPress hacking and wpscan testing DO NOT EXPOSE THIS TO INTERNET! Installation $ git clone githubcom/vavkamil/dvwpgit $ cd dvwp/ $ docker-compose up -d --build $ docker-compose run --rm wp-cli install-wp Usage $ docker-compose up -d $ docker-compose down