Impact
The WP Webhooks plugin, in all releases up to 3.3.5, accepts user‑supplied input without proper validation, allowing an unauthenticated attacker to copy arbitrary files from the web server to arbitrary destinations. This flaw can be leveraged to read the wp‑config.php file and expose database credentials, severely compromising confidentiality and potentially enabling further attacks. The vulnerability carries a CVSS score of 9.8, indicating critical severity.
Affected Systems
The vulnerability affects the WP Webhooks plugin developed by cozmoslabs, used to automate tasks within WordPress. All installations of WP Webhooks version 3.3.5 or earlier are impacted. No later versions are listed as vulnerable.
Risk and Exploitability
Given the missing authentication checks, the attack vector is likely an unauthenticated HTTP request to a plugin endpoint that processes file copy operations. Although the EPSS score is less than 1%, indicating a low current exploitation probability, the high CVSS score and the potential for credential leakage warrant urgent attention. The flaw is not listed in CISA KEV, but the impact remains critical. An attacker with network access to the site could exploit the flaw without any special credentials, leading to local file disclosure and potential compromise of the entire WordPress installation.
OpenCVE Enrichment
EUVD