PT-2022-3501 · WordPress · Custom-Content-Type-Manager

Iain Wallace

·

Published

2022-07-06

·

Updated

2022-07-14

·

CVE-2015-3173

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions custom-content-type-manager Wordpress plugin (affected versions not specified)
Description The issue is related to incorrect code generation management in the custom-content-type-manager plugin for WordPress. It allows a remote attacker to execute arbitrary PHP code. This can be achieved by an administrator, enabling arbitrary remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04282
CVE-2015-3173

Affected Products

Custom-Content-Type-Manager