HIGH

CVE-2018-20463

CVSS v3

7.5

HIGH

EPSS Score

76.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

Technical details

Published
12/25/2018

Frequently asked questions

What is CVE-2018-20463?

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

Is CVE-2018-20463 actively exploited?

Active exploitation of CVE-2018-20463 has not been confirmed. The EPSS score is 76.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-20463?

CVE-2018-20463 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2018-20463 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.