Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05105
HistoryJan 14, 2022 - 12:00 a.m.

WordPress WP Coder plugin file contains vulnerability

2022-01-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wordpress
php
file inclusion
vulnerability
arbitrary code execution
security

EPSS

0.001

Percentile

48.4%

WordPress is the WordPress Foundation’s set of blogging platforms developed using the PHP language. The WordPress WP Coder plugin has a file inclusion vulnerability in versions prior to 2.5.2, which stems from the fact that the wow-company administration menu page does not effectively filter calls to remote file resources, and can be exploited to include arbitrary files with PHP extensions to execute arbitrary code.

EPSS

0.001

Percentile

48.4%