14 Jul

Arbitrary Directory Download Vulnerability in Download Theme

Recently we found that the plugin Download Plugin plugin contained an arbitrary directory download vulnerability. The Download Theme plugin is from the same developer and has very similar code, which leads to it having the same vulnerability. Other than the AJAX function and function it connects to being named differently, the only difference is that you don’t need to include a input for the value “f” as well as the directory when making the request to exploit this vulnerability.

Proof of Concept

The following proof of concept will ZIP up the website’s files and prompt you to download them.

Make sure to replace “[path to WordPress]” with the location of WordPress.

http://[path to WordPress]/wp-admin/admin-post.php?dtwap_download=../../

Timeline

  • 7/7/2016 – Developer notified.
  • 7/14/2016 – WordPress.org Plugin Directory notified.
  • 7/14/2016 – Removed from WordPress.org Plugin Directory.
  • 7/21/2016 – Version 1.0.3 released, which fixes vulnerability.

Concerned About The Security of the Plugins You Use?

When you order a plugin security review from us we review the plugin for issues that hackers would exploit if the knew about them as well as making sure that that needed security checks have been implemented in the plugin. If you order two reviews you will receive free lifetime subscription to our service.

Leave a Reply

Your email address will not be published. Required fields are marked *