Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-20148. PoCs published by nth347.
AI-analyzed exploit summary This exploit leverages PHAR deserialization in WordPress via XML-RPC to achieve remote code execution (RCE). It uploads a malicious polyglot file, manipulates metadata to trigger deserialization, and executes arbitrary commands.
Description
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
Exploits (1)
This exploit leverages PHAR deserialization in WordPress via XML-RPC to achieve remote code execution (RCE). It uploads a malicious polyglot file, manipulates metadata to trigger deserialization, and executes arbitrary commands.
References (10)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H