Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the Visual Composer Website Builder plugin for WordPress, allowing unauthenticated attackers to potentially execute arbitrary code on the server. This could lead to the compromise of sensitive data or the bypass of security controls. The main concern is confirming relevance and exposure, as this type of vulnerability could significantly impact systems accessible via the internet.
- Unauthenticated attackers can run code on servers.
- Affects WordPress sites using Visual Composer plugin.
- Confirm if this plugin is used and exposed.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can leverage a weakness in the Visual Composer Website Builder plugin to include and execute arbitrary files on a WordPress server. This attack targets the `vcv-template` parameter, enabling the attacker to bypass security measures, access sensitive information, or execute code if certain file types can be uploaded and then included.
- No authentication needed.
- `vcv-template` parameter allows file inclusion.
- Leads to sensitive data exposure or code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to include and execute arbitrary files on the server. When supported by the advisory, this may lead to the execution of any PHP code within those files, potentially enabling attackers to bypass access controls, acquire sensitive data, or achieve code execution, especially if image or other file type uploads are permitted and subsequently included.
- Server files could be compromised.
- Arbitrary file inclusion and execution.
- Sensitive data exposure and code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Visual Composer Website Builder plugin for WordPress is susceptible to Local File Inclusion, allowing unauthenticated attackers to execute arbitrary files on the server. This vulnerability, present in all versions up to 45.16.0, can lead to bypassing access controls, data exfiltration, or code execution. Given the plugin's typical deployment in public-facing WordPress sites, immediate action is required to identify affected instances, confirm business criticality and reachability, assign ownership, and plan remediation.
- Identify accountable application or platform owners.
- Verify affected instances and their reachability.
- Plan remediation and coordinate with vendors.