HIGH

CVE-2018-12895

CVSS v3

8.8

HIGH

EPSS Score

89.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.

Technical details

Published
6/26/2018

Frequently asked questions

What is CVE-2018-12895?

WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.

Is CVE-2018-12895 actively exploited?

Active exploitation of CVE-2018-12895 has not been confirmed. The EPSS score is 89.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-12895?

CVE-2018-12895 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2018-12895 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.