{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/verdure-core-1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-78562"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Verdure Core (1.2)"],"_cs_severities":["high"],"_cs_tags":["lfi","wordpress","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Mikado-Themes"],"content_html":"\u003cp\u003eThe Verdure Core plugin for WordPress contains a Local File Inclusion (LFI) vulnerability in all versions up to and including 1.2. This vulnerability stems from the improper control of filenames passed to PHP include or require statements (CWE-98). An unauthenticated attacker can manipulate the input parameters processed by the plugin to force the inclusion of arbitrary files present on the server. If an attacker can successfully upload a file containing malicious PHP code - such as an image file containing embedded shell code - they can trigger the execution of this code by including the file via the vulnerable parameter. This flaw allows for remote code execution, sensitive data exposure, and bypass of standard access controls within the WordPress environment. Defenses should focus on immediate patching or disabling the plugin until an update is applied.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance on the target WordPress site to identify the use of the Verdure Core plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload, often hidden within a file type allowed by the site (e.g., a manipulated image file or text file containing PHP tags).\u003c/li\u003e\n\u003cli\u003eAttacker uses the site's legitimate file upload functionality to store the payload on the web server.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the parameter used by the Verdure Core plugin that handles file inclusion.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP request to the vulnerable endpoint, setting the inclusion parameter to point to the previously uploaded malicious file path.\u003c/li\u003e\n\u003cli\u003eThe web server process interprets the included file as PHP, executing the embedded malicious commands.\u003c/li\u003e\n\u003cli\u003eAttacker gains a webshell or executes arbitrary system-level commands with the privileges of the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary PHP code on the underlying web server. This can lead to full site compromise, exfiltration of sensitive database information (such as wp-config.php containing database credentials), or the establishment of persistent backdoors. As a widely used framework, WordPress sites are frequent targets for such automated LFI exploitation campaigns, potentially resulting in unauthorized administrative access or the use of the server as a pivot point for further network movement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Verdure Core plugin to the latest available version that patches this vulnerability.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, deactivate or remove the Verdure Core plugin from all WordPress instances.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect and block HTTP requests containing path traversal sequences (e.g., ../, ..%2f) or suspicious file extensions in parameters targeted by the plugin.\u003c/li\u003e\n\u003cli\u003eEnable detailed web server access logging and monitor for anomalous HTTP requests targeting files in uploads directories that coincide with suspicious status codes or unusual query strings.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to exploit LFI via webserver log telemetry.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T10:07:51Z","date_published":"2026-08-25T10:07:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-verdure-core-lfi/","summary":"An unauthenticated Local File Inclusion vulnerability in Verdure Core versions 1.2 and earlier allows remote attackers to execute arbitrary PHP code on affected WordPress sites.","title":"Local File Inclusion Vulnerability in Verdure Core WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-verdure-core-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Verdure Core (1.2)","version":"https://jsonfeed.org/version/1.1"}