WordPress: Unauthenticated path traversal leading to conditional RCE
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
WordPress: Unauthenticated path traversal leading to conditional RCE
Unofficial Hacker News client; not affiliated with Y Combinator.
tptacek · · focus · HN ↗
vntok · · focus · HN ↗
That is dangerously incorrect, a whole lot of themes are vulnerable. The main pre-condition, "presence of a top-level directory named 'page-xxx' like 'page-templates' in the theme's directory" is actually an official recommendation in the WordPress documentation.
See here: <a href="https://developer.wordpress.org/themes/classic-themes/templates/page-template-files/" rel="nofollow">https://developer.wordpress.org/themes/classic-themes/templa...
> As discussed in Organizing Theme Files, WordPress can recognize page templates stored in the theme’s root folder or in a first-level subdirectory of the theme folder. *The page-templates/ folder is a common convention* for organizing global page templates, but it is not required. Page templates can also be stored in other first-level subdirectories, such as templates/ or page_templates/.
AlienRobot · · focus · HN ↗
On a fresh WP install, a random user can't upload PHP files. Normally you don't even need to allow random users to register an account since avatars on comments come from gravatar anyway.
vntok · · focus · HN ↗
Indeed, but you don't need to upload anything as long as there's already a PHP file that allows you to execute arbitrary commands somewhere on the server, right?
Well, as it turns out, the default PHP Docker image has had such a file readily available until version 8.5 =)
AlienRobot · · focus · HN ↗
vntok · · focus · HN ↗
- especially the functions that are explicitely exposed to be used on front-facing interfaces (ie: templating functions).
- and especially when the security flaw in question was not only raised 9 years ago but described in details on the official documentation page of the affected function