vendor:
wpStoreCart
by:
Sammy FORGIT
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: wpStoreCart
Affected Version From: 2.5.27
Affected Version To: 2.5.29
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wpstorecart
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
WordPress Plugins – wpStoreCart Arbitrary File Upload Vulnerability
An arbitrary file upload vulnerability exists in the wpStoreCart plugin for WordPress. A remote attacker can exploit this vulnerability to upload arbitrary PHP code and execute it in the context of the webserver process. The vulnerable plugin version is 2.5.27 - 2.5.29. An attacker can use the Google Dork 'inurl:/wp-content/plugins/wpstorecart/' to find vulnerable websites. The exploit code is a PHP script that uses cURL to upload a malicious PHP file to the vulnerable website. The uploaded file can be accessed at http://www.example.com/wordpress/wp-content/uploads/wpstorecart/lo.php.
Mitigation:
Upgrade to the latest version of the wpStoreCart plugin.