Record summary

CVE-2020-36728 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to reset and gain full control of a site.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 7, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 28, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.5.5affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File UploadCVSS 6.5

The Adning Advertising plugin for WordPress versions below 1.5.6 is vulnerable to arbitrary file upload, allowing attackers to upload malicious files to the server.

Impact

Unauthenticated attackers can upload malicious files to achieve remote code execution, potentially compromising the entire WordPress site and server.

Remediation

Upgrade to Adning Advertising version 1.5.6 or later.

Authorsiamnoooob, pdresearch
Template tagscvecve202wordpresswpwp-pluginintrusivefile-uploadadningrcevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CPE: cpe:2.3:a:tunasite:adning_advertising:*:*:*:*:*:wordpress:*:*
FOFA: body="served by Adning"

Source: ProjectDiscovery

References

5