Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3C1ADB7C-0A5A-4359-8A61-0579BF99F6F1
HistoryDec 09, 2023 - 12:00 a.m.

Astra Pro < 4.3.2 - Authenticated(Contributor+) Remote Code Execution via Metabox

2023-12-0900:00:00
wpscan.com
16
wordpress
astra pro
remote code execution
metabox
authenticated access

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

18.2%

Description The Astra Pro Addon plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.3.1 via the ast-advanced-hook-php-code meta field. This makes it possible for authenticated attackers, with contributor access and above, to execute code on the server.

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

18.2%

Related for WPVDB-ID:3C1ADB7C-0A5A-4359-8A61-0579BF99F6F1