CVE-2023-54352
CRITICALWP Travel Kit Travelscape - WordPress Seotheme Remote Code Execution Unauthenticated
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2023-54352. PoCs published by Milad karimi.
AI-analyzed exploit summary This exploit targets a WordPress plugin/theme vulnerability (CVE-2023-54352) to achieve unauthenticated remote code execution by uploading a malicious PHP shell. It checks for the presence of a specific file (`mar.php`) in vulnerable paths and writes successful targets to output files.
Description
WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and upload additional files for persistent access.
Exploits (1)
This exploit targets a WordPress plugin/theme vulnerability (CVE-2023-54352) to achieve unauthenticated remote code execution by uploading a malicious PHP shell. It checks for the presence of a specific file (`mar.php`) in vulnerable paths and writes successful targets to output files.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H