Adaptive Images for WordPress <= 0.6.66 - Local File Inclusion
Strategic Overview
- Status
- Patched in 0.6.67
- Affected Plugin
- Adaptive Images for WordPress
- Affected Version
< 0.6.67- CVSS
- 7.5High
- Weakness type
- CWE-98 · Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
- CVE
CVE-2019-14205
At a glance
CVE-2019-14205 is a high-severity Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in the Adaptive Images for WordPress WordPress plugin, affecting versions < 0.6.67. It carries a CVSS score of 7.5 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 0.6.67; sites on affected versions should update now. Disclosed July 2019, reported by Mark Gruffer.
Vulnerability Overview
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality.
CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Adaptive Images for WordPress < 0.6.67 carries this weakness at adaptive-images-settings, and reaching it takes a caller who can reach the endpoint. PHP file inclusion means a path used by include or require is built from request data, so the file that gets executed is under the caller's influence.
Including an attacker-influenced file executes its contents, which is why this class is routinely chained with an upload or log-poisoning step to reach code execution. For Adaptive Images for WordPress the fix is 0.6.67: builds < 0.6.67 are affected, anything from 0.6.67 onward is not.
Remediation
Update to version 0.6.67, or a newer patched version
How does WordSec protect against this?
The attempt arrives as an ordinary request to Adaptive Images for WordPress: WordSec's web application firewall inspects request payloads before WordPress loads them. Classes like this one can leave something behind, so the staged malware scanner is the second half: it looks for dropped files and modified code rather than for the request that created them. None of that substitutes for the fix: Adaptive Images for WordPress 0.6.67 closes this, and updating the plugin is the step that ends it.
- Firewall
- Scanner
- Alerts
External References
Related records
Other vulnerabilities in Adaptive Images for WordPress
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C