‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. 0xbadcafebee · · focus · HN ↗
      Themes whose banner you can google for. If those sites have pearcmd.php is available, they're using the official Docker php image, and/or using default cPanel, the site is vulnerable, afaict. Basically a drive-by exploit for anyone with some google-fu.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.