S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-20463 Scanner

CVE-2018-20463 scanner - Local File Inclusion (LFI) vulnerability in JSmol2WP plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-20463
7.5
CVSS

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The JSmol2WP plugin 1.07 for WordPress is a tool designed to enhance website visitors' experience by providing an interactive way to visualize chemical structures and molecular information. This plugin enables website owners to integrate JSmol, a free and open-source web-based viewer for chemical structures, into their WordPress websites. By doing so, visitors can rotate, zoom, and manipulate the 3D models of molecules, making the learning process more engaging and informative.

Unfortunately, the usage of JSmol2WP plugin 1.07 for WordPress has been jeopardized by the CVE-2018-20463 vulnerability. This vulnerability allows an attacker to read arbitrary files on the server by navigating up from the directory root, also known as directory traversal. The issue resides in the jsmol.php file of the plugin, where the "query" parameter is not properly sanitized. As a result, an attacker can craft a query string containing "../" sequences to access files outside the intended directory.

The exploitation of this vulnerability can lead to a range of severe consequences, depending on the file that the attacker gains access to. For instance, if the attacker gains access to the website's configuration file, they can retrieve sensitive information such as login credentials and database credentials. Moreover, the attacker can use this vulnerability for Server-Side Request Forgery (SSRF), which enables them to make HTTP requests from the server and launch further attacks against external resources.

In summary, the JSmol2WP plugin 1.07 for WordPress has a serious vulnerability that allows attackers to read arbitrary files on the server. This vulnerability can have significant consequences, including data theft and SSRF. To protect against this vulnerability, website owners should implement several measures such as updating the plugin and hardening the server's security. By using the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets and stay informed about potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Update the JSmol2WP plugin to the latest version that fixes the vulnerability.
  • Implement input validation and sanitization to prevent directory traversal attacks.
  • Restrict server permissions by adjusting the file system permissions for the plugin files.
  • Monitor and log any suspicious activity that involves the plugin's files.
  • Harden the server's security by implementing a firewall and intrusion detection system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-20463 scanner - Local File Inclusion (LFI) vulnerability in JSmol2WP plugin for WordPress | S4E