CVE-2020-36842
HIGH EXPLOITEDWPvivid Migration, Backup, Staging < 0.9.35 - Authenticated Arbitrary File Upload via AJAX Actions
Title source: llmExploitation Summary
CVE-2020-36842 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2020-36842, targeting an arbitrary file upload vulnerability in the WPvivid WordPress plugin (versions up to 0.9.35). The exploit authenticates, uploads a malicious ZIP file, and achieves remote code execution by extracting the payload to a web-accessible directory.
Description
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.
Exploits (2)
The repository contains a functional Python exploit for CVE-2020-36842, targeting an arbitrary file upload vulnerability in the WPvivid WordPress plugin (versions up to 0.9.35). The exploit authenticates, uploads a malicious ZIP file, and achieves remote code execution by extracting the payload to a web-accessible directory.
This repository contains a functional Python exploit for CVE-2020-36842, an arbitrary file upload vulnerability in the WPvivid WordPress plugin (versions up to 0.9.35). The exploit automates version checking, authentication, file upload, and extraction to achieve remote code execution via a malicious ZIP file.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H