CVE-2024-3105
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server.
El complemento Woody code snippets – Insert Header Footer Code, AdSense Ads para WordPress es vulnerable a la ejecución remota de código en todas las versiones hasta la 2.5.0 incluida a través del código corto 'insert_php'. Esto se debe a que el complemento no restringe el uso de la funcionalidad a usuarios autorizados de alto nivel. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, ejecuten código en el servidor.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-29 CVE Reserved
- 2024-06-14 CVE Published
- 2024-08-09 CVE Updated
- 2024-08-10 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (5)
URL | Date | SRC |
---|---|---|
https://github.com/hunThubSpace/CVE-2024-3105-PoC | 2024-08-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webcraftic Search vendor "Webcraftic" | Woody Code Snippets – Insert Header Footer Code, AdSense Ads Search vendor "Webcraftic" for product "Woody Code Snippets – Insert Header Footer Code, AdSense Ads" | <= 2.5.0 Search vendor "Webcraftic" for product "Woody Code Snippets – Insert Header Footer Code, AdSense Ads" and version " <= 2.5.0" | en |
Affected
|