CVSS v3
8.8
HIGH
EPSS Score
89.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
Technical details
- Published
- 2018-06-26
Frequently asked questions
What is CVE-2018-12895?
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
Is CVE-2018-12895 actively exploited?
Active exploitation of CVE-2018-12895 has not been confirmed. The EPSS score is 89.0%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2018-12895?
CVE-2018-12895 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2018-12895 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2018 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).