What the vulnerability does
01Description
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
Explanation of Vulnerability in Simple Terms
An authenticated administrator with high privileges can trigger arbitrary file upload and code execution on a WordPress site running Hover Effects plugin version 2.1 or earlier. The vulnerability requires the attacker to have admin access and the site owner to interact with a malicious link or page. This allows an attacker to upload files and execute PHP code, compromising the entire site.
What an attacker can do
Upload arbitrary files and execute PHP code on the site if they have admin access.
Potential impact on your site
A compromised admin account can upload malicious files and run code, leading to full site takeover.
Conditions required to exploit
Attacker must have WordPress administrator privileges and the site owner must click a malicious link or visit a page.
Key dates
External resources