vendor:
WordPress
by:
sucuri.net @sucurisecurity
7,5
CVSS
HIGH
PHP Code Injection
94
CWE
Product Name: WordPress
Affected Version From: <3.3.1
Affected Version To: 3.3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wordpress:4.7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MSWin32
2017
WordPress 4.7.0/4.7.1 Plugin Insert PHP – PHP Code Injection
You Can Inject PHP Code INTO Pages via Wordpress REST API Vulnerability. The PoC involves sending a POST request to the WordPress REST API with a malicious payload in the content field.
Mitigation:
Disable the Insert PHP plugin or upgrade to version 3.3.1 or later.