Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6297

Опубликовано: 25 июн. 2024
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

Ссылки

EPSS

Процентиль: 88%
0.03969
Низкий

10 Critical

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 10
github
больше 1 года назад

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

EPSS

Процентиль: 88%
0.03969
Низкий

10 Critical

CVSS3

Дефекты