CVE-2018-25436 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2018-25436 requires immediate attention.
· 7 min read
Executive Summary
CVE-2018-25436 is a critical unauthenticated file upload flaw in WordPress Plugin Baggage Freight Shipping Australia 0.1.0 (CVSS 9.8). An attacker can send crafted POST requests to the upload-package.php endpoint and upload arbitrary files with malicious extensions. Because the plugin moves uploaded files without proper validation, this can lead to remote code execution on the WordPress host.
There is no known exploitation in the wild and it is not in CISA KEV, but the impact is severe enough that solo developers and small teams should treat this as an emergency. If you use this plugin, assume compromise is possible until you verify the site is patched or the plugin is removed.
Immediate Action
- Disable or remove the plugin now if you do not absolutely need it. If a fixed version is unavailable, deactivate it immediately and plan a replacement.
- Block direct access to
upload-package.phpat the web server or WAF level while you investigate. - Inspect the plugin directory for unexpected PHP files, web shells, or recently modified uploads.
- Rotate credentials for WordPress admins, hosting panels, SFTP/SSH, and database access if the site was exposed publicly.
- Take a backup before cleanup so you can preserve evidence, then restore from a known-good snapshot if compromise is confirmed.
- Check for any vendor notice or patch page: vendor advisory / plugin release notes.
Affected Versions
baggage-freight-shipping-australia@0.1.0vulnerablebaggage-freight-shipping-australia@<=0.1.0vulnerable- Safe version:
TODO_FIXED_VERSIONor later, if a patched release exists - If no fixed release exists: remove the plugin and replace it with a maintained alternative
Resolution Guide
WordPress / plugin removal:
# From the WordPress admin UI: Plugins -> Deactivate -> Delete
# Or via WP-CLI
wp plugin deactivate baggage-freight-shipping-australia
wp plugin delete baggage-freight-shipping-australia
Web server hardening while you respond:
# Apache: block direct access to the vulnerable upload handler
<Files "upload-package.php">
Require all denied
</Files>
# Nginx: deny access to the endpoint
location = /wp-content/plugins/baggage-freight-shipping-australia/upload-package.php {
deny all;
}
Docker / image guidance:
# Rebuild from a clean base and remove the plugin from the image
docker build --no-cache -t your-site:clean .
# If you pin image tags, move to a known-good tag after validation
docker pull your-site:TODO_FIXED_TAG
Linux package managers: this is a WordPress plugin issue, so apt/yum will not patch it directly. Use them only to update the web stack and PHP runtime:
sudo apt update && sudo apt upgrade -y
sudo yum update -y
JavaScript / Python / Java ecosystems: not directly applicable to this WordPress plugin, but if your deployment pipeline packages the site or scans dependencies, update your security tooling and lockfiles as needed. Example placeholders:
# npm/yarn/pnpm: not applicable to this WordPress plugin
# pip/pipx: not applicable
# Maven/Gradle: not applicable
Minimal code fix pattern if you maintain a fork or custom plugin code:
<?php
// Reject unauthenticated uploads and validate file type strictly
if ( ! current_user_can('upload_files') ) {
wp_die('Forbidden', 403);
}
$allowed = array('jpg', 'jpeg', 'png', 'pdf');
$ext = strtolower(pathinfo($_FILES['file']['name'], PATHINFO_EXTENSION));
if ( ! in_array($ext, $allowed, true) ) {
wp_die('Invalid file type', 400);
}
// Use WordPress upload APIs and never move raw files blindly
$upload = wp_handle_upload($_FILES['file'], array('test_form' => false));
if ( isset($upload['error']) ) {
wp_die($upload['error'], 400);
}
Detection & Verification
Check whether the plugin is installed:
wp plugin list | grep -i baggage
find wp-content/plugins -maxdepth 1 -type d | grep -i baggage
Check the version:
grep -R "Version:" wp-content/plugins/baggage-freight-shipping-australia/ -n
wp plugin get baggage-freight-shipping-australia --field=version
Look for suspicious files and recent changes:
find wp-content/plugins/baggage-freight-shipping-australia -type f \( -name "*.php" -o -name "*.phtml" -o -name "*.phar" \) -mtime -14 -ls
grep -R "upload-package.php" -n wp-content/plugins/baggage-freight-shipping-australia/
grep -R "move_uploaded_file\|wp_handle_upload" -n wp-content/plugins/baggage-freight-shipping-australia/
Verify the fix:
# Confirm the plugin is gone or disabled
wp plugin is-active baggage-freight-shipping-australia && echo "STILL ACTIVE" || echo "inactive"
# Confirm the endpoint is blocked
curl -i -X POST https://example.com/wp-content/plugins/baggage-freight-shipping-australia/upload-package.php
# Expected result: 403, 404, or a server-denied response
Dependency/security scanning:
# WordPress-focused inventory
wp plugin list --status=active
# File integrity check if you have a baseline
sha256sum wp-content/plugins/baggage-freight-shipping-australia/*
Risk and Impact
This flaw can let an attacker upload a malicious PHP file and execute code on your server without logging in. From there, they may steal database credentials, deface the site, plant persistence, or pivot into other services on the same host. For small teams, the blast radius can include the entire WordPress instance, customer data, and any secrets stored on the server.
If you run this plugin in production, the safest assumption is that the attack path is trivial and fast. Remove or isolate the plugin first, then investigate for compromise before bringing the site fully back online.