CVE-2023-6634
HIGH EXPLOITED NUCLEILearnPress <4.2.5.7 - Command Injection
Title source: llmExploitation Summary
CVE-2023-6634 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including krn966. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-6634, targeting a deserialization vulnerability in the LearnPress WordPress plugin (versions up to 4.2.5.7). The exploit constructs malicious payloads to achieve remote code execution via the `load_content_via_ajax` endpoint.
Description
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.
Exploits (1)
This repository contains a functional Python exploit for CVE-2023-6634, targeting a deserialization vulnerability in the LearnPress WordPress plugin (versions up to 4.2.5.7). The exploit constructs malicious payloads to achieve remote code execution via the `load_content_via_ajax` endpoint.
Nuclei Templates (1)
http.html:/wp-content/plugins/learnpress
body=/wp-content/plugins/learnpress
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H