S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-16283 Scanner

CVE-2018-16283 scanner - Directory Traversal vulnerability in Wechat Broadcast plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16283
9.8
CVSS

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Wechat Broadcast plugin for WordPress is a tool that enables website owners to quickly and conveniently send mass notifications to their users via the WeChat messaging service. With this plugin, website administrators can easily broadcast important updates, promotions, and other announcements to their followers. It is a popular plugin and has been widely used by businesses, bloggers, and developers all over the world.

However, users of the Wechat Broadcast plugin need to be aware of the CVE-2018-16283 vulnerability that affects versions 1.2.0 and earlier. This vulnerability allows an attacker to perform directory traversal attacks, which means that they can access files and folders outside of the expected directory. Attackers can exploit this vulnerability by appending "../" to the Image.php URL parameter, which allows them to access sensitive files that should not be publicly accessible.

The exploitation of CVE-2018-16283 could lead to several security risks for websites that use the Wechat Broadcast plugin. Attackers could access password files, configuration files, and other sensitive data, which can lead to data breaches or system misuse. Furthermore, attackers could modify and replace essential files, which can lead to website downtime or even complete destruction of the website.

In conclusion, the Wechat Broadcast plugin for WordPress is a useful tool that can simplify website communication with users. However, users need to be aware of the CVE-2018-16283 vulnerability and take the necessary precautions to protect against it. With the pro features of the s4e.io platform, website owners can quickly and easily learn about vulnerabilities in their digital assets and take measures to improve their website security.

 

REFERENCES

Solution Advice

To protect against CVE-2018-16283, website administrators can take the following precautions:

  • Upgrade to the latest version of the Wechat Broadcast plugin, which has the vulnerability fixed.
  • Restrict access to the Image.php file, so that it can only be accessed by authenticated users.
  • Implement proper input validation to ensure that the Image.php URL parameter only contains valid characters and directory names.
  • Use a web application firewall (WAF) that can detect and block directory traversal attacks.
  • Regularly monitor website logs and file permissions to detect any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16283 scanner - Directory Traversal vulnerability in Wechat Broadcast plugin for WordPress | S4E