WP01 Plugin for WordPress Arbitrary File Download Vulnerability
Vulnerability
A vulnerability allowing arbitrary file download has been identified in the WP01 plugin for WordPress, affecting all versions through 2.6.2. The issue arises from a missing capability check and inadequate restrictions on the make_archive() function, enabling authenticated attackers with Subscriber-level access and above to download and access the contents of arbitrary files on the server, potentially exposing sensitive information.
Impact
Exploitation of this vulnerability allows for unauthorized access to sensitive files on the server, which could lead to the disclosure of confidential information.
Reproduction
To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send a request to the WordPress site using the 'wp01_generate_zip_archive' AJAX action. The request must include the 'target' and 'path' parameters, specifying the file to be downloaded and its path on the server. The vulnerable plugin will then create a ZIP archive containing the specified file and make it available for download.
Remediation
No known patch is available for this vulnerability. Users are advised to uninstall the affected plugin and consider finding a replacement.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
