QID 730372
Date Published: 2022-03-17
QID 730372: WordPress Plugin Hypertext Preprocessor (PHP) Everywhere Remote Code Execution (RCE) Vulnerability
PHP Everywhere is a WordPress plugin that is intended to allow site owners to execute PHP code anywhere on their site. It included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes.
Affected Versions:
PHP Everywhere versions 2.0.3 and prior.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the PHP Everywhere.
Successful exploitation of this vulnerability could allow any authenticated user of any level, even subscribers and customers, to execute code on a site with the plugin installed.
Solution
Customers are requested to update to Starter Templates version 2.0.4 or later to mitigate this vulnerability.
Vendor References
CVEs related to QID 730372
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PHP Everywhere |
|