CVE-2018-16299
HIGH NUCLEILocalize My Post 1.0 - Path Traversal via AJAX Include File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-16299. PoCs published by Manuel García Cárdenas. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in WordPress Plugin Localize My Post 1.0. The vulnerability arises from unsanitized user input in the 'file' parameter, allowing an attacker to include arbitrary local files via directory traversal.
Description
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in WordPress Plugin Localize My Post 1.0. The vulnerability arises from unsanitized user input in the 'file' parameter, allowing an attacker to include arbitrary local files via directory traversal.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N