Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-44223

Опубликовано: 25 нояб. 2021
Источник: debian
EPSS Средний

Описание

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed5.8.1+dfsg1-1package
wordpressno-dsabullseyepackage
wordpressno-dsabusterpackage
wordpressno-dsastretchpackage

Примечания

  • WordPress 5.8 introduces a new "Update URI" plugin header. Further mitigation

  • options documented in:

  • https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/

  • https://make.wordpress.org/core/2021/06/29/introducing-update-uri-plugin-header-in-wordpress-5-8/

EPSS

Процентиль: 97%
0.39871
Средний

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

CVSS3: 8.1
nvd
больше 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

github
около 3 лет назад

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

EPSS

Процентиль: 97%
0.39871
Средний