Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability impacts WordPress sites using the WP Travel Engine plugin, a tool for managing tour bookings. It allows unauthenticated attackers to delete files on the server, potentially leading to full system compromise. The core issue lies in how the plugin handles user profile image uploads, specifically a lack of proper file path validation.
- Attackers can delete server files without logging in.
- It enables remote code execution for significant impact.
- Confirm plugin relevance and check for exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could target a WordPress website using the WP Travel Engine plugin. By sending a crafted request to the plugin's profile image handling feature, the attacker could trick the server into deleting critical files. If a file like `wp-config.php` is deleted, this could lead to remote code execution.
- No authentication required.
- Improper file path validation allows deletion.
- Arbitrary file deletion can lead to code execution.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could potentially delete arbitrary files on a WordPress server, which could lead to remote code execution if critical files like `wp-config.php` are targeted. This vulnerability exists within the WP Travel Engine plugin, affecting its ability to properly validate file paths during profile image updates.
- Server files could be deleted.
- Improper path validation allows deletion.
- Remote code execution is possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
Given the vulnerability in the WP Travel Engine plugin, application owners and platform teams are likely responsible for remediation. The first practical step is to identify all WordPress instances using this plugin, assess their exposure and business criticality, and then confirm the accountable owner for each instance before planning a coordinated response.
- Application owners must be accountable.
- Verify plugin usage and exposure.
- Plan remediation based on risk.