nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2278 CVE-2023-2278
CRITICAL
WP Directory Kit <= 1.1.9 - Unauthenticated Local File Inclusion via wdk_public_action
Record summary
CVE-2023-2278 has a selected CVSS score of 9.8 (critical).
Description
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Directory KitBrowse wpdirectorykit / WP Directory KitDefault status: unaffected | CVE List | Through 1.1.9 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/wpdirectorykit/tags/1.1.8/vendor/Winter_MVC/core/mvc_loader.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2904689/wpdirectorykit/trunk/vendor/Winter_MVC/core/mvc_loader.php wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/87399a07-d2d8-42cd-81f0-9060f6cfff48?source=cve