QID 730498
Date Published: 2022-05-25
QID 730498: WordPress Arbitrary Remote Code Execution (RCE) Vulnerability
WordPress is software designed for everyone, emphasizing accessibility, performance, security, and ease of use.
CVE-2021-44223: WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Affected Versions:
WordPress versions prior to 5.8
QID Detection Logic:
The QID checks for the version via the meta generator tag or tries to fingerprint using BE.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code via a supply-chain attack.
For more Information Please visit WordPress 5.8
CVEs related to QID 730498
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress 5.8 |
|