vendor:
wp-google-drive
by:
Lenon Leite
8.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: wp-google-drive
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE: CVE-2018-9077
CPE: 2.2:wordpress:wp-google-drive
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.1
2018
Plugin Google Drive for WordPress 2.2 – RCE – Unlik
A vulnerability exists in Plugin Google Drive for WordPress 2.2, where the $_POST['file_name'] parameter is not escaped, allowing an attacker to send malicious data form and execute arbitrary code. No login is required to exploit this vulnerability.
Mitigation:
Upgrade to the latest version of Plugin Google Drive for WordPress.