CVE-2018-12895
CVSS v3
8.8
HIGH
Score EPSS
62.2 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
Détails techniques
- Publiée le
- 2018-06-26
Questions fréquentes
Qu’est-ce que CVE-2018-12895 ?
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
CVE-2018-12895 est-elle activement exploitée ?
Aucune exploitation active de CVE-2018-12895 n’est confirmée. Son score EPSS était de 62.2 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2018-12895 ?
CVE-2018-12895 a un score de base CVSS v3 de 8.8 (gravité HIGH).
CVE-2018-12895 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2018 à trier
Classées par probabilité d’exploitation (EPSS).