CVE-2016-15004
InfiniteWP Client Plugin injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.
Se ha encontrado una vulnerabilidad en el plugin de cliente InfiniteWP versiones 1.5.1.3/1.6.0. Ha sido declarada como crítica. Esta vulnerabilidad afecta a una funcionalidad desconocida. La manipulación conlleva a una inyección. El ataque puede ser lanzado remotamente. La actualización a versión 1.6.1.1 puede abordar este problema. Es recomendado actualizar el componente afectado
The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the site.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-01-25 CVE Published
- 2022-07-19 CVE Reserved
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-10-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.96073 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Revmakx Search vendor "Revmakx" | Infinitewp Client Search vendor "Revmakx" for product "Infinitewp Client" | 1.5.1.3 Search vendor "Revmakx" for product "Infinitewp Client" and version "1.5.1.3" | wordpress |
Affected
| ||||||
Revmakx Search vendor "Revmakx" | Infinitewp Client Search vendor "Revmakx" for product "Infinitewp Client" | 1.6.0 Search vendor "Revmakx" for product "Infinitewp Client" and version "1.6.0" | wordpress |
Affected
|