668
VMScore

CVE-2021-44223

Published: 25/11/2021 Updated: 30/11/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

WordPress prior to 5.8 lacks support for the Update URI plugin header. This makes it easier for remote malicious users to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Github Repositories

WordPress Plugin Update Confusion

WordPress Plugin Update Confusion Simple tool to detect websites vulnerable to a novel supply chain attack targeting unclaimed WordPress plugins Update: the scanner is no longer working, as WordPressorg is now returning fake data from the API endpoint used to verify the number of active installations - twittercom/vavkamil/status/1468221819098484741 Read more: Please