Lucene search

K
wpvulndbWpvulndbWPVDB-ID:508415D3-39FC-4C92-8DE3-686DB2A7E6C8
HistorySep 20, 2023 - 12:00 a.m.

Allow PHP in Posts and Pages < 3.0.4 - Authenticated Remote Code Execution (RCE)

2023-09-2000:00:00
wpscan.com
8
wordpress
remote code execution
authenticated

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

36.5%

Description The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution via the ‘php’ shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

36.5%

Related for WPVDB-ID:508415D3-39FC-4C92-8DE3-686DB2A7E6C8