QID 730728

Date Published: 2023-02-20

QID 730728: WordPress Plugin ImageMagick Engine Insecure Deserialization Vulnerability

Wordpress Plugin ImageMagick Engine helps in improving the quality of re-sized images.

Wordpress Plugin ImageMagick Engine is vulnerable to deserialization of untrusted input via the 'cli_path' parameter.

Affected Versions:
ImageMagick Engine plugin versions prior to 1.7.6

NOTE:
It was found that ImageMagick Engine plugin versions 1.7.4 and 1.7.5 has no difference. QID will be posting ImageMagick Engine plugin version 1.7.5 as 1.7.4

QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the ImageMagick Engine plugin.

Successful exploitation of this vulnerability may allow an unauthenticated attackers to upload malicious file and execute commands on the target.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to install ImageMagick Engine 1.7.6 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730728

    Software Advisories
    Advisory ID Software Component Link
    ImageMagick Engine Release Notes URL Logo wordpress.org/plugins/imagemagick-engine/#developers