Page MenuHomePhabricator
Authored By
stefano.cannillo
Feb 13 2024, 2:58 PM
Size
19 KB
Referenced Files
None
Subscribers
None

wpscan20240213_before.txt

_______________________________________________________________
__ _______ _____
\ \ / / __ \ / ____|
\ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
\ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
\ /\ / | | ____) | (__| (_| | | | |
\/ \/ |_| |_____/ \___|\__,_|_| |_|
WordPress Security Scanner by the WPScan Team
Version 3.8.22
Sponsored by Automattic - https://automattic.com/
@_WPScan_, @ethicalhack3r, @erwan_lr, @firefart
_______________________________________________________________
[i] It seems like you have not updated the database for some time.
[?] Do you want to update now? [Y]es [N]o, default: [N]y
[i] Updating the Database ...
[i] Update completed.
[+] URL: https://www.wikimedia.it/ [51.75.90.142]
[+] Started: Mon Feb 12 23:58:05 2024
Interesting Finding(s):
[+] Headers
| Interesting Entry: Server: Apache/2.4.38 (Debian)
| Found By: Headers (Passive Detection)
| Confidence: 100%
[+] robots.txt found: https://www.wikimedia.it/robots.txt
| Found By: Robots Txt (Aggressive Detection)
| Confidence: 100%
[+] This site has 'Must Use Plugins': https://www.wikimedia.it/wp-content/mu-plugins/
| Found By: Direct Access (Aggressive Detection)
| Confidence: 80%
| Reference: http://codex.wordpress.org/Must_Use_Plugins
[+] The external WP-Cron seems to be enabled: https://www.wikimedia.it/wp-cron.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 60%
| References:
| - https://www.iplocation.net/defend-wordpress-from-ddos
| - https://github.com/wpscanteam/wpscan/issues/1299
[+] WordPress version 6.3 identified (Insecure, released on 2023-08-08).
| Found By: Style Etag (Aggressive Detection)
| - https://www.wikimedia.it/wp-admin/load-styles.php, Match: '6.3'
| Confirmed By: Query Parameter In Install Page (Aggressive Detection)
| - https://www.wikimedia.it/wp-includes/css/dashicons.min.css?ver=6.3
| - https://www.wikimedia.it/wp-includes/css/buttons.min.css?ver=6.3
| - https://www.wikimedia.it/wp-admin/css/forms.min.css?ver=6.3
| - https://www.wikimedia.it/wp-admin/css/l10n.min.css?ver=6.3
| - https://www.wikimedia.it/wp-admin/css/install.min.css?ver=6.3
|
| [!] 9 vulnerabilities identified:
|
| [!] Title: WP 6.3-6.3.1 - Contributor+ Stored XSS via Footnotes Block
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/63270b61-dddd-4cc0-a091-a04cb4f682ec
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP 5.6-6.3.1 - Contributor+ Stored XSS via Navigation Block
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/cd130bb3-8d04-4375-a89a-883af131ed3a
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38000
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP 5.6-6.3.1 - Reflected XSS via Application Password Requests
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/da1419cc-d821-42d6-b648-bdb3c70d91f2
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP < 6.3.2 - Denial of Service via Cache Poisoning
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/6d80e09d-34d5-4fda-81cb-e703d0e56e4f
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP < 6.3.2 - Subscriber+ Arbitrary Shortcode Execution
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/3615aea0-90aa-4f9a-9792-078a90af7f59
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP < 6.3.2 - Contributor+ Comment Disclosure
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/d35b2a3d-9b41-4b4f-8e87-1b8ccb370b9f
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39999
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WP < 6.3.2 - Unauthenticated Post Author Email Disclosure
| Fixed in: 6.3.2
| References:
| - https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5561
| - https://wpscan.com/blog/email-leak-oracle-vulnerability-addressed-in-wordpress-6-3-2/
| - https://wordpress.org/news/2023/10/wordpress-6-3-2-maintenance-and-security-release/
|
| [!] Title: WordPress < 6.4.3 - Deserialization of Untrusted Data
| Fixed in: 6.3.3
| References:
| - https://wpscan.com/vulnerability/5e9804e5-bbd4-4836-a5f0-b4388cc39225
| - https://wordpress.org/news/2024/01/wordpress-6-4-3-maintenance-and-security-release/
|
| [!] Title: WordPress < 6.4.3 - Admin+ PHP File Upload
| Fixed in: 6.3.3
| References:
| - https://wpscan.com/vulnerability/a8e12fbe-c70b-4078-9015-cf57a05bdd4a
| - https://wordpress.org/news/2024/01/wordpress-6-4-3-maintenance-and-security-release/
[+] WordPress theme in use: wmi
| Location: https://www.wikimedia.it/wp-content/themes/wmi/
| Style URL: https://www.wikimedia.it/wp-content/themes/wmi/style.css?ver=e1685792335ac05194dfde2b7c7ca81b
| Style Name: Wikimedia.it
| Style URI: https://emeraldcommunication.com
| Description: Wikimedia theme based on "betheme theme"...
| Author: Emerald Communnication
| Author URI: https://emeraldcommunication.com
|
| Found By: Css Style In Homepage (Passive Detection)
| Confirmed By: Css Style In 404 Page (Passive Detection)
|
| Version: 1.0.1 (80% confidence)
| Found By: Style (Passive Detection)
| - https://www.wikimedia.it/wp-content/themes/wmi/style.css?ver=e1685792335ac05194dfde2b7c7ca81b, Match: 'Version: 1.0.1'
[+] Enumerating All Plugins (via Passive Methods)
[+] Checking Plugin Versions (via Passive and Aggressive Methods)
[i] Plugin(s) Identified:
[+] addon-elements-for-elementor-page-builder
| Location: https://www.wikimedia.it/wp-content/plugins/addon-elements-for-elementor-page-builder/
| Last Updated: 2024-02-05T06:15:00.000Z
| [!] The version is out of date, the latest version is 1.12.12
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| [!] 1 vulnerability identified:
|
| [!] Title: Elementor Addon Elements < 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
| Fixed in: 1.12.12
| References:
| - https://wpscan.com/vulnerability/4c090a45-2a85-4f59-a1b9-104891032d0f
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0834
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/6ebb5654-ba3e-4f18-8720-a6595a771964
|
| Version: 1.12.9 (50% confidence)
| Found By: Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/addon-elements-for-elementor-page-builder/readme.txt
[+] elementor
| Location: https://www.wikimedia.it/wp-content/plugins/elementor/
| Last Updated: 2024-02-07T15:41:00.000Z
| [!] The version is out of date, the latest version is 3.19.2
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| [!] 5 vulnerabilities identified:
|
| [!] Title: Elementor Website Builder < 3.16.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_inline_svg()
| Fixed in: 3.16.5
| References:
| - https://wpscan.com/vulnerability/62b53acf-6551-4ea7-8727-039a3c9ba7ce
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47505
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/b44ef21f-464e-487a-ba5a-fe889e4c488c
|
| [!] Title: Elementor Website Builder < 3.16.5 - Missing Authorization to Arbitrary Attachment Read
| Fixed in: 3.16.5
| References:
| - https://wpscan.com/vulnerability/e60f0f7e-4c3b-4107-803a-8e03526859ed
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-47504
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/c873c76a-144e-4945-8fa2-c9ffe0e3c061
|
| [!] Title: Elementor < 3.18.2 - Contributor+ Arbitrary File Upload to RCE via Template Import
| Fixed in: 3.18.2
| References:
| - https://wpscan.com/vulnerability/a6b3b14c-f06b-4506-9b88-854f155ebca9
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48777
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/5b6d0a38-ac28-41c9-9da1-b30b3657b463
|
| [!] Title: Elementor < 3.19.1 - Authenticated(Contributor+) Arbitrary File Deletion and PHAR Deserialization
| Fixed in: 3.19.1
| References:
| - https://wpscan.com/vulnerability/4d7dfcc6-8c32-4e0d-b3bb-7e2685916e2b
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24934
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/4915b769-9499-40ac-835e-279e3a910558
|
| [!] Title: Elementor Website Builder – More than Just a Page Builder < 3.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt
| Fixed in: 3.19.0
| References:
| - https://wpscan.com/vulnerability/57af46d9-9a26-4085-9829-e0add7893332
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0506
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/4473d3f6-e324-40f5-b92b-167f76b17332
|
| Version: 3.15.2 (100% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://www.wikimedia.it/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=3.15.2
| - https://www.wikimedia.it/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=3.15.2
| Confirmed By:
| Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/elementor/readme.txt
| Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/elementor/readme.txt
[+] essential-addons-for-elementor-lite
| Location: https://www.wikimedia.it/wp-content/plugins/essential-addons-for-elementor-lite/
| Last Updated: 2024-02-11T11:58:00.000Z
| [!] The version is out of date, the latest version is 5.9.9
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| [!] 8 vulnerabilities identified:
|
| [!] Title: Essential Addons for Elementor < 5.9.3 - Contributor+ Stored XSS
| Fixed in: 5.9.3
| References:
| - https://wpscan.com/vulnerability/10a73fea-68b4-4861-8ac1-b5ac278fed11
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-7044
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/6e770e98-3c13-4e37-b51b-4c39bce2cb42
|
| [!] Title: Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scripting via Image URl
| Fixed in: 5.9.5
| References:
| - https://wpscan.com/vulnerability/6955630f-29c0-4996-9184-325ea153dfcf
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0585
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/417baa1c-29f0-4fec-8008-5b52359b3328
|
| [!] Title: Essential Addons for Elementor < 5.9.5 - Contributor+ Stored Cross-Site Scritping
| Fixed in: 5.9.5
| References:
| - https://wpscan.com/vulnerability/427af876-f60c-4219-b5de-1c72b41c0136
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0586
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/c00ff4bd-d846-4e3f-95ed-2a6430c47ebf
|
| [!] Title: Essential Addons for Elementor < 5.9.8 - Contributor+ Stored XSS
| Fixed in: 5.9.8
| References:
| - https://wpscan.com/vulnerability/d6f1740c-9e31-4be1-81ff-62bfd5b568fe
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0954
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/875db71d-c799-40b9-95e1-74d53046b0a9
|
| [!] Title: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+ Stored Cross-Site Scripting via Filterable Gallery
| Fixed in: 5.9.9
| References:
| - https://wpscan.com/vulnerability/49240593-fb6a-4d8c-a369-c4606cd9ee24
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1171
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/fafdd087-9637-41df-bc5a-97e1a02ea744
|
| [!] Title: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+ Stored Cross-Site Scripting via Accordion
| Fixed in: 5.9.9
| References:
| - https://wpscan.com/vulnerability/0a8dde9a-bac0-498d-a68e-466a29401a08
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1172
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/f2ff2cc6-b584-442b-890b-033a0a047c24
|
| [!] Title: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+ Stored Cross-Site Scripting
| Fixed in: 5.9.9
| References:
| - https://wpscan.com/vulnerability/538a02f8-1aac-4f5e-ad22-7b98745be27e
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1276
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/af8bee01-15bc-485e-8b01-8b68b199b34d
|
| [!] Title: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders < 5.9.9 - Contributor+ Stored Cross-Site Scripting
| Fixed in: 5.9.9
| References:
| - https://wpscan.com/vulnerability/5e0c33f9-178d-42ca-bc5f-f1354be951e5
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1236
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/43014ecd-72d9-44cc-be24-c0c9790ddc20
|
| Version: 5.9 (100% confidence)
| Found By: Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt
| Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt
[+] gdpr-cookie-compliance
| Location: https://www.wikimedia.it/wp-content/plugins/gdpr-cookie-compliance/
| Last Updated: 2024-01-26T15:04:00.000Z
| [!] The version is out of date, the latest version is 4.13.1
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| Version: 4.12.5 (100% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://www.wikimedia.it/wp-content/plugins/gdpr-cookie-compliance/dist/styles/gdpr-main.css?ver=4.12.5
| - https://www.wikimedia.it/wp-content/plugins/gdpr-cookie-compliance/dist/scripts/main.js?ver=4.12.5
| Confirmed By: Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/gdpr-cookie-compliance/readme.txt
[+] gravityforms
| Location: https://www.wikimedia.it/wp-content/plugins/gravityforms/
| [!] The version is out of date, the latest version is 2.8.3.1
|
| Found By: Urls In 404 Page (Passive Detection)
|
| Version: 2.7.12 (90% confidence)
| Found By: Query Parameter (Passive Detection)
| - https://www.wikimedia.it/wp-content/plugins/gravityforms/js/jquery.json.min.js?ver=2.7.12
| - https://www.wikimedia.it/wp-content/plugins/gravityforms/js/gravityforms.min.js?ver=2.7.12
| - https://www.wikimedia.it/wp-content/plugins/gravityforms/js/placeholders.jquery.min.js?ver=2.7.12
| Confirmed By: Change Log (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/gravityforms/change_log.txt, Match: '### 2.7.12'
[+] smart-slider-3
| Location: https://www.wikimedia.it/wp-content/plugins/smart-slider-3/
| Latest Version: 3.5.1.21 (up to date)
| Last Updated: 2023-11-15T12:46:00.000Z
|
| Found By: Urls In Homepage (Passive Detection)
|
| Version: 3.5.1.21 (100% confidence)
| Found By: Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/smart-slider-3/readme.txt
| Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/smart-slider-3/readme.txt
[+] w3-total-cache
| Location: https://www.wikimedia.it/wp-content/plugins/w3-total-cache/
| Last Updated: 2023-11-28T16:04:00.000Z
| [!] The version is out of date, the latest version is 2.6.1
|
| Found By: Comment Debug Info (Passive Detection)
|
| Version: 2.4.1 (100% confidence)
| Found By: Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/w3-total-cache/readme.txt
| Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/w3-total-cache/readme.txt
[+] wiki-embed
| Location: https://www.wikimedia.it/wp-content/plugins/wiki-embed/
| Latest Version: 1.4.6 (up to date)
| Last Updated: 2013-08-13T23:08:00.000Z
|
| Found By: Urls In Homepage (Passive Detection)
| Confirmed By: Urls In 404 Page (Passive Detection)
|
| Version: 1.4.6 (80% confidence)
| Found By: Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/wiki-embed/readme.txt
[+] wordpress-seo
| Location: https://www.wikimedia.it/wp-content/plugins/wordpress-seo/
| Last Updated: 2024-02-06T08:57:00.000Z
| [!] The version is out of date, the latest version is 22.0
|
| Found By: Comment (Passive Detection)
|
| [!] 1 vulnerability identified:
|
| [!] Title: Yoast SEO < 21.1 - Authenticated (Seo Manager+) Stored Cross-Site Scripting
| Fixed in: 21.1
| References:
| - https://wpscan.com/vulnerability/42b355cc-d7b6-474d-8578-9c1a99b1e3c7
| - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40680
| - https://www.wordfence.com/threat-intel/vulnerabilities/id/385a82ff-50ad-4787-845b-fb5f639f6466
|
| Version: 20.13 (100% confidence)
| Found By: Comment (Passive Detection)
| - https://www.wikimedia.it/, Match: 'optimized with the Yoast SEO plugin v20.13 -'
| Confirmed By:
| Readme - Stable Tag (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/wordpress-seo/readme.txt
| Readme - ChangeLog Section (Aggressive Detection)
| - https://www.wikimedia.it/wp-content/plugins/wordpress-seo/readme.txt
[+] Enumerating Config Backups (via Passive and Aggressive Methods)
Checking Config Backups - Time: 00:00:16 <==================================================================================================================================> (137 / 137) 100.00% Time: 00:00:16
[i] No Config Backups Found.
[+] WPScan DB API OK
| Plan: free
| Requests Done (during the scan): 11
| Requests Remaining: 14
[+] Finished: Mon Feb 12 23:58:39 2024
[+] Requests Done: 230
[+] Cached Requests: 7
[+] Data Sent: 73.464 KB
[+] Data Received: 20.272 MB
[+] Memory used: 272.23 MB
[+] Elapsed time: 00:00:33

File Metadata

Mime Type
text/plain
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
14589853
Default Alt Text
wpscan20240213_before.txt (19 KB)

Event Timeline