S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-7422 Scanner

CVE-2018-7422 scanner - Local File Inclusion (LFI) vulnerability in Site Editor plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-7422
7.5
CVSS

A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Site Editor plugin is a popular add-on for WordPress that allows users to easily customize and edit the appearance and content of their website. With this plugin, users can create and modify pages, design forms, tweak fonts and colors, and even add new features and functions to their site. The Site Editor plugin is widely used by website owners, web designers, and developers who want to create high-quality and professional-looking websites with ease.

However, the Site Editor plugin also has a serious security flaw that can put websites at risk. This vulnerability, known as CVE-2018-7422, allows remote attackers to exploit the plugin's Local File Inclusion (LFI) vulnerability and retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php. This means that an attacker can potentially gain access to sensitive information stored on a website's server, including passwords, usernames, and configuration files.

The consequences of this vulnerability can be severe and far-reaching. With access to sensitive files and data, attackers can compromise the security and integrity of a website, steal sensitive information, and even use the website as a platform for further attacks. This can lead to financial losses, damage to reputation and credibility, and legal liabilities. The vulnerability can also affect the website's users, who may have their personal and confidential information compromised.

At s4e.io, we understand the importance of protecting your digital assets. That's why we offer a comprehensive security platform that allows you to easily and quickly identify vulnerabilities and risks in your website and other online assets. With our pro features, you can stay ahead of potential security threats and protect your website from malicious attacks. So don't wait – sign up for s4e.io today and keep your digital assets safe and secure.

 

REFERENCES

Solution Advice

Fortunately, there are steps that website owners and administrators can take to protect against this vulnerability. These include:

  • Keeping the Site Editor plugin up to date and applying any security patches or updates as soon as they become available.
  • Limiting access to sensitive files and directories on the server, and ensuring that user permissions are properly configured.
  • Using firewalls and other security measures to prevent unauthorized access to the website's server.
  • Monitoring the website for suspicious activity and unusual file access.
  • Regularly testing the website for vulnerabilities and weaknesses, and proactively addressing any issues that are discovered.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-7422 scanner - Local File Inclusion (LFI) vulnerability in Site Editor plugin for WordPress | S4E