VDB
CVE-2018-12895
CVE-2018-12895
PUBLISHED
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.
EPSS 62.56% · 99.1th percentile
Risk Scores
EPSS Score
62.56%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | wordpress | 0, 4.3+dfsg-1, 4.3.1+dfsg-1 |
| Ubuntu:18.04:LTS | wordpress | 4.8.2+dfsg-2, 4.9.1+dfsg-1, * |
Timeline
- Jun 26, 2018 CVE Published
- Jul 30, 2018 PoC Published
- Apr 14, 2021 EPSS Score
- Oct 25, 2021 PoC Published
- Feb 4, 2022 EPSS Score
- May 8, 2023 EPSS Score
- Oct 26, 2023 EPSS Score
- Dec 27, 2023 EPSS Score
- May 5, 2024 EPSS Score
- Jul 11, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-12895 third-party-advisory
- https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12895 third-party-advisory