Record summary

CVE-2018-20985 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Payeezy Pay <=2.97 - Local File InclusionCVSS 9.8

WordPress Plugin WP Payeezy Pay is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Payeezy Pay version 2.97 is vulnerable; prior versions are also affected.

Impact

The vulnerability allows an attacker to include local files and execute arbitrary code on the server.

Remediation

Update to the latest version of WordPress Payeezy Pay plugin.

WeaknessesCWE-20
Authorsdaffainfo
Template tagscvecve2018wordpresslfipluginpayeezyvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:payeezy:wp_payeezy_pay:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2