CVE-2020-36705
Adning Advertising <= 1.5.5 - Arbitrary File Upload
Record summary
CVE-2020-36705 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 7, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Adning AdvertisingBrowse tunafish / Adning AdvertisingDefault status: unaffected | CVE List | Through 1.5.5 | affected |
adning_advertisingBrowse tunasite / adning_advertising | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALAdning Advertising <= 1.5.5 - Arbitrary File UploadCVSS 9.8
The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Impact
Unauthenticated attackers can upload malicious files to achieve remote code execution, potentially compromising the entire WordPress site and server.
Remediation
Fixed in 1.5.6
Source: ProjectDiscovery