CVE-2018-25329
HIGHWordPress Plugin WP with Spritz 1.0 Remote File Inclusion
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25329. PoCs published by Wadeek.
AI-analyzed exploit summary The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the WordPress plugin WP with Spritz 1.0. It leverages the 'url' parameter in 'wp.spritz.content.filter.php' to include arbitrary local or remote files, such as '/etc/passwd' or a remote shell script.
Description
WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensitive files like system configuration and credentials.
Exploits (1)
The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the WordPress plugin WP with Spritz 1.0. It leverages the 'url' parameter in 'wp.spritz.content.filter.php' to include arbitrary local or remote files, such as '/etc/passwd' or a remote shell script.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N