CVE-2018-16283
Description
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
In plain language
AI Act nowThe wechat brodcast WordPress plugin version 1.2.0 or earlier can let strangers read files from your web server, so affected sites should act now.
Unauthenticated directory traversal in wechat brodcast's Image.php `url` parameter allows remote arbitrary-file read on vulnerable WordPress installations.
What to do now
- Check your WordPress Plugins list for wechat brodcast and confirm its version; version 1.2.0 or earlier is affected.
- Disable and remove the plugin from affected sites until a verified replacement or vendor fix is available.
- There is no verified fixed version currently available; do not rely on a routine update as remediation.
- Ask your IT provider to check server logs for unusual requests to the plugin's image page and change exposed site or database passwords if suspicious activity is found.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-16283 and every CVE in our database. Create a free account — no credit card required.
Create Free Account