Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-10019.
PoCs published by Sammy, including Metasploit module exploits/unix/webapp/wp_frontend_editor_file_upload.
AI-analyzed exploit summary This Metasploit module exploits an authenticated file upload vulnerability in the WordPress Front-end Editor plugin (CVE-2012-10019), allowing arbitrary PHP file uploads via a custom upload mechanism. The exploit uploads a PHP payload and triggers it to achieve remote code execution.
Description
The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Exploits (1)
This Metasploit module exploits an authenticated file upload vulnerability in the WordPress Front-end Editor plugin (CVE-2012-10019), allowing arbitrary PHP file uploads via a custom upload mechanism. The exploit uploads a PHP payload and triggers it to achieve remote code execution.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H