漏洞描述
WordPress Plugin WP Payeezy Pay is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Payeezy Pay version 2.97 is vulnerable; prior versions are also affected.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.pluginvulnerabilities.comhttps://www.pluginvulnerabilities.com/2018/12/06/our-improved-proactive-monitoring-has-now-caught-a-local-file-inclusion-lfi-vulnerability-as-well/↗wordpress.orghttps://wordpress.org/plugins/wp-payeezy-pay/#developers↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-20985↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/ARPSyndicate/cvemon↗