Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44223

Опубликовано: 25 нояб. 2021
Источник: debian

Описание

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed5.8.1+dfsg1-1package
wordpressno-dsabullseyepackage
wordpressno-dsabusterpackage
wordpressno-dsastretchpackage

Примечания

  • WordPress 5.8 introduces a new "Update URI" plugin header. Further mitigation

  • options documented in:

  • https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/

  • https://make.wordpress.org/core/2021/06/29/introducing-update-uri-plugin-header-in-wordpress-5-8/

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

CVSS3: 8.1
nvd
почти 4 года назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

github
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.