Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjhj-x5j3-wcrf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

EPSS

Процентиль: 98%
0.63797
Средний

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

EPSS

Процентиль: 98%
0.63797
Средний

Дефекты

CWE-434