CVE-2020-36728
Adning Advertising <= 1.5.5 - Unauthenticated Arbitrary File Deletion via Path Traversal
Record summary
CVE-2020-36728 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to reset and gain full control of a site.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 7, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 28, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Adning AdvertisingBrowse tunafish / Adning AdvertisingDefault status: unaffected | CVE List | Through 1.5.5 | affected |
adning_advertisingBrowse tunasite / adning_advertising | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File UploadCVSS 6.5
The Adning Advertising plugin for WordPress versions below 1.5.6 is vulnerable to arbitrary file upload, allowing attackers to upload malicious files to the server.
Impact
Unauthenticated attackers can upload malicious files to achieve remote code execution, potentially compromising the entire WordPress site and server.
Remediation
Upgrade to Adning Advertising version 1.5.6 or later.
Source: ProjectDiscovery