CVE-2018-12895
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
EPSS 89.59% · 99.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | wordpress | 0, 4.3+dfsg-1, 4.3.1+dfsg-1 |
| Ubuntu:18.04:LTS | wordpress | 4.8.2+dfsg-2, 4.9.1+dfsg-1, * |
Exploit Intelligence
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc-repo)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc)
- Hotfix for file deletion to to code execution vulnerability in WordPress (github-poc)
…and 16 more exploits
Timeline
- Jun 26, 2018 CVE Published
- Jul 30, 2018 PoC Published
- Apr 14, 2021 EPSS Score
- Oct 25, 2021 PoC Published
- Feb 4, 2022 EPSS Score
- May 8, 2023 EPSS Score
- Oct 26, 2023 EPSS Score
- Dec 27, 2023 EPSS Score
- May 5, 2024 EPSS Score
- Jul 11, 2024 EPSS Score
- Aug 5, 2024 CVE Updated
- Mar 17, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-12895 third-party-advisory
- https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12895 third-party-advisory