CVE-2015-10135
CRITICALWPshop 2 - E-Commerce < 1.3.9.6 - Unauthenticated Arbitrary File Upload via ajaxUpload Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-10135.
PoCs published by g0blin, including Metasploit module exploits/unix/webapp/wp_wpshop_ecommerce_file_upload.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress WPshop eCommerce plugin (versions 1.3.3.3 to 1.3.9.5), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and execute the payload.
Description
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Exploits (1)
This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress WPshop eCommerce plugin (versions 1.3.3.3 to 1.3.9.5), allowing remote code execution by uploading a malicious PHP file. The exploit leverages a multipart form data upload to bypass restrictions and execute the payload.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H