QID 731138

Date Published: 2024-02-07

QID 731138: WordPress Simple Firewall Builder Local File Inclusion Vulnerability

The WordPress Simple Firewall is the only WordPress security plugin that protects itself - it will prevent access to its own settings so that unauthorized users can't deactivate or screw with your security settings.

CVE-2023-6989 :This vulnerability is limited to just the inclusion of PHP files, however, it could be leveraged by an attacker who has the ability to upload PHP files but can not directly access those files to execute.

Affected Versions:
WordPress Simple-firewall plugin versions prior to 18.5.10

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Simple- Firewall Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow attackers to perform any action the logged in administrator they targeted is allowed to do on the targeted site including installing arbitrary plugins and creating new rogue Administrator users.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to WP ERP version 18.5.10 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731138

    Software Advisories
    Advisory ID Software Component Link
    wp-simple-firewall plugin URL Logo wordpress.org/plugins/wp-simple-firewall/#developers