CRITICAL

CVE-2018-12426

CVSS v3

9.8

CRITICAL

EPSS Score

10.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.

Technical details

Published
7/2/2018

Frequently asked questions

What is CVE-2018-12426?

The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.

Is CVE-2018-12426 actively exploited?

Active exploitation of CVE-2018-12426 has not been confirmed. The EPSS score is 10.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-12426?

CVE-2018-12426 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-12426 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.