CVE-2018-12426: Malicious File Upload
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remoteupload request with a .php filename and the image/jpeg content type.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12426?
CVE-2018-12426 is a vulnerability in the WP Live Chat Support Pro plugin for WordPress that allows unauthenticated remote code execution.
What is the severity of CVE-2018-12426?
CVE-2018-12426 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2018-12426?
CVE-2018-12426 can be exploited by sending a v1/remote_upload request with a .php filename and the image/jpeg content type.
Is authentication required to exploit CVE-2018-12426?
No, CVE-2018-12426 can be exploited without authentication.
Is there a patch or fix available for CVE-2018-12426?
Yes, the WP Live Chat Support Pro plugin has released version 8.0.07 which fixes the vulnerability.