vendor:
Wordpress
by:
leonjza
6,1
CVSS
MEDIUM
Content Injection
94
CWE
Product Name: Wordpress
Affected Version From: 4.7.0
Affected Version To: 4.7.1
Patch Exists: YES
Related CWE: CVE-2017-5490
CPE: a:wordpress:wordpress
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
WordPress 4.7.0/4.7.1 Unauthenticated Content Injection PoC
This exploit allows an unauthenticated user to inject malicious content into a Wordpress website. The vulnerability is present in Wordpress versions 4.7.0 and 4.7.1, and can be exploited by sending a specially crafted request to the Wordpress REST API. This can be used to inject malicious content into the website, such as JavaScript code, which can be used to steal user data or perform other malicious activities.
Mitigation:
Wordpress users should update to the latest version of Wordpress to patch this vulnerability.