S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-43160 Scanner

CVE-2024-43160 Scanner - Arbitrary File Upload vulnerability in BerqWP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-43160
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
BerqWPby BerqWP
n/a
berqwpby berqier
0
Updated Sep 10, 2026View on NVD →
Detail

BerqWP is a WordPress plugin aimed at optimizing website speed through features like Core Web Vitals, caching, CDN, image optimization, CSS, and JavaScript adjustments. It is widely used by website administrators and developers seeking to enhance site performance and ensure faster loading times. The tool is designed for integration with WordPress sites, making it applicable for both personal blogs and professional business sites. Installed on websites looking to boost their search engine rankings, it helps in reducing page load times significantly. BerqWP is a versatile tool that appeals to technical users who manage their own site hosting and are knowledgeable about plugin installations and configurations. Due to its functionalities, the plugin is popular among those looking to meet modern web performance standards.

The vulnerability in BerqWP relates to the possibility of arbitrary file upload due to missing file type validation. This security vulnerability exists in all versions up to and including 1.7.6. Attackers can exploit this flaw to upload malicious files to the server hosting the WordPress site using the BerqWP plugin. By doing so, the attackers could potentially execute code on the server, achieve data exfiltration, or deploy further attacks. As the vulnerability does not require authentication, it poses a significant risk to any site using the affected plugin version. Quick identification and remediation of this vulnerability are therefore essential to maintain site integrity and security.

The Arbitrary File Upload vulnerability is particularly concerning due to the lack of input validation in the plugin's /api/store_webp.php file. Attackers can bypass security measures by uploading file types that are not typically allowed, exploiting the server's trust in file type correctness. The vulnerability is exploited via a POST request, which doesn't check for appropriate file extensions or types, culminating in potential file execution. The endpoint serves as a gateway for uploading files and does not verify the legitimacy or intent of the submitted content, leading to this security gap. Attackers could utilize this vulnerability in conjunction with other exploits to ensure persistence on the network or platform.

If the vulnerability is exploited, attackers can gain unauthorized access to the site’s host, leading to data leaks, defacement, or deployment of ransomware. Malicious files uploaded could compromise the site's availability, integrity, and confidentiality, causing significant harm. The exploitation may allow for the installation of scripts and malware, leading to further network penetration or denial of service attacks. Backend access could be obtained, leading to data manipulation or theft. This gap also risks damaging the organization’s reputation, potentially leading to loss of user trust and a downturn in web traffic.

REFERENCES

Solution Advice
  • Update the BerqWP plugin to the latest version that addresses this vulnerability.
  • Implement file type validation to restrict file uploads to only accepted types.
  • Regularly review and audit server logs for unusual activity related to file uploads.
  • Implement security plugins that can provide additional layers of protection and scanning.
  • Restrict permissions for the directories where files are uploaded to limit potential exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-43160 Scanner - Arbitrary File Upload vulnerability in BerqWP | S4E