Executive brief
The Google Drive for WordPress plugin, which allows users to back up and manage files via Google Drive, contains a security flaw that allows unauthorized individuals to access sensitive server files. By exploiting this vulnerability, an attacker can read critical configuration files, such as those containing database credentials, potentially leading to a full site takeover or data breach. This issue does not require a login or any user interaction to execute.
Technical details
A path traversal vulnerability exists in the Google Drive for WordPress plugin version 2.2 due to insufficient sanitization of the 'file_name' parameter in the 'gdrive-ajaxs.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request with the 'ajaxstype' parameter set to 'del_fl_bkp' and a 'file_name' containing traversal sequences (e.g., '../../wp-config.php'). This allows the attacker to bypass directory restrictions and read arbitrary files on the server, including sensitive WordPress configuration files containing database credentials. While some sources mention Remote Code Execution (RCE), the primary mechanism described is file disclosure via path traversal.
Affected products
- Google Drive for WordPress Google Drive for WordPress (wp-google-drive) 2.2
Timeline
- 2017-11-25: other: Vulnerability discovered
- 2017-12-26: other: Vendor contacted
- 2018-04-08: disclosed: Public disclosure and exploit published
- 2026-05-17: advisory: CVE-2018-25326 published to NVD