blog.nintechnet.com
https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin CVE-2019-17232
HIGHNuclei
etoilewebdesign ultimate_faq Missing Authentication for Critical Function
Record summary
CVE-2019-17232 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 30, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ultimate_faqBrowse etoilewebdesign / ultimate_faq | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Ultimate FAQs <= 1.8.24 – Unauthenticated Options Import and ExportCVSS 7.5
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Impact
Unauthenticated attackers can import arbitrary FAQs and configuration through CSV upload, potentially injecting malicious content or extracting existing FAQ data from the WordPress site.
Remediation
Update the Ultimate FAQs plugin to version 1.8.25 or later.
WeaknessesCWE-306
Authorsdaffainfo
Template tagscvecve2019wordpresswp-pluginwpultimate-faqsunauthintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CPE: cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/ultimate-faqs"
FOFA: body="/wp-content/plugins/ultimate-faqs"
https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin/ https://nvd.nist.gov/vuln/detail/CVE-2019-17232 https://wordpress.org/plugins/ultimate-faqs/#developers https://wpvulndb.com/vulnerabilities/9883
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17232 wordpress.org
https://wordpress.org/plugins/ultimate-faqs wpvulndb.com
https://wpvulndb.com/vulnerabilities/9883