Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the VikAppointments Services Booking Calendar WordPress plugin. This issue allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to unauthorized code execution by targeting critical system files. Exploitation is dependent on specific configurations involving file-type custom fields.
- Attackers can delete server files remotely.
- Critical risk if booking plugin is in use.
- Confirm relevance and verify exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by leveraging a published File-type custom field on a confirmation page. Since the plugin does not adequately validate file paths in its extract function, an unauthenticated attacker can trick the system into deleting arbitrary files on the server. This could lead to critical system compromise, such as remote code execution, if a vital file like the configuration file is deleted.
- No authentication required.
- Unsanitized file path input.
- Arbitrary file deletion, potential RCE.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to delete arbitrary files on the server, potentially leading to remote code execution. This risk is present when a File-type custom field is published on the confirmation page shortcode, which is not a default configuration.
- Arbitrary file deletion on server.
- Unauthenticated deletion via custom field.
- Potential for remote code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress plugin's arbitrary file deletion vulnerability likely falls under the responsibility of the application owner or the platform team managing the WordPress environment. The initial practical step is to identify all instances of the VikAppointments plugin, confirm if any are configured with file-type custom fields on confirmation pages, and determine their exposure and criticality. Once these factors are assessed, a remediation plan can be formulated.
- Application owners should own the issue.
- Verify plugin usage and custom field configuration.
- Plan remediation based on identified risk.