‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. vntok · · focus · HN ↗
      > This is a somewhat situational Wordpress RCE that impacts only a couple themes. reply

      That is dangerously incorrect, a whole lot of themes are vulnerable. The main pre-condition, "presence of a top-level directory named 'page-xxx' like 'page-templates' in the theme's directory" is actually an official recommendation in the WordPress documentation.

      See here: <a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;themes&#x2F;classic-themes&#x2F;templates&#x2F;page-template-files&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;themes&#x2F;classic-themes&#x2F;templa...

      &gt; As discussed in Organizing Theme Files, WordPress can recognize page templates stored in the theme’s root folder or in a first-level subdirectory of the theme folder. *The page-templates&#x2F; folder is a common convention* for organizing global page templates, but it is not required. Page templates can also be stored in other first-level subdirectories, such as templates&#x2F; or page_templates&#x2F;.

      1. dawnerd · · focus · HN ↗
        Yeah not sure why you’re being downvoted when the built in themes are vulnerable as is the default docker image pre php8.5 which a lot of people use as a base and I bet a lot of hosting providers use as well behind the scenes.
      2. AlienRobot · · focus · HN ↗
        I&#x27;m not sure I understand. That&#x27;s the main pre-condition... to include an arbitrary PHP that is already in the server.

        On a fresh WP install, a random user can&#x27;t upload PHP files. Normally you don&#x27;t even need to allow random users to register an account since avatars on comments come from gravatar anyway.

        1. vntok · · focus · HN ↗
          &gt; On a fresh WP install, a random user can&#x27;t upload PHP files.

          Indeed, but you don&#x27;t need to upload anything as long as there&#x27;s already a PHP file that allows you to execute arbitrary commands somewhere on the server, right?

          Well, as it turns out, the default PHP Docker image has had such a file readily available until version 8.5 =)

          1. AlienRobot · · focus · HN ↗
            Jesus. I don&#x27;t think WP is nice to use, but people are saying WP is crap because someone else made pearcmd.php that allows you to run arbitrary commands, and then a third someone else included that in the default PHP docker image. In this case all PHP CMS&#x27;s are a directory traversal bug away from this CVE.
            1. vntok · · focus · HN ↗
              Indeed. Then again, it&#x27;s on WordPress not to have directory traversal flaws in their core functions...

              - especially the functions that are explicitely exposed to be used on front-facing interfaces (ie: templating functions).

              - and especially when the security flaw in question was not only raised 9 years ago but described in details on the official documentation page of the affected function

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.