Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-10143.
PoCs published by Marc-Alexandre Montpas, Christian Mehlmauer, including Metasploit module exploits/unix/webapp/wp_platform_exec.
AI-analyzed exploit summary This Metasploit module exploits a file upload vulnerability in the WordPress Platform theme, allowing remote code execution by uploading a malicious PHP file via an unchecked admin_init call. The payload is delivered through a multipart form data POST request.
Description
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Exploits (1)
This Metasploit module exploits a file upload vulnerability in the WordPress Platform theme, allowing remote code execution by uploading a malicious PHP file via an unchecked admin_init call. The payload is delivered through a multipart form data POST request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H