vendor:
Social Warfare Plugin Wordpress
by:
Luka Sikic
6.1
CVSS
MEDIUM
Remote Code Execution
78
CWE
Product Name: Social Warfare Plugin Wordpress
Affected Version From: <=3.5.2
Affected Version To: <=3.5.2
Patch Exists: YES
Related CWE: CVE-2019-9978
CPE: a:warfareplugins:social_warfare
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
RCE in Social Warfare Plugin WordPress ( <=3.5.2 )
A remote code execution vulnerability exists in Social Warfare Plugin Wordpress version <=3.5.2. An attacker can exploit this vulnerability by sending a crafted request to the vulnerable server. This will allow the attacker to execute arbitrary code on the vulnerable server.
Mitigation:
Upgrade to the latest version of Social Warfare Plugin Wordpress.