PT-2024-11032 · WordPress · Social Warfare

Raed Ahsan

·

Published

2024-01-17

·

Updated

2024-10-21

·

CVE-2021-4434

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Social Warfare plugin for WordPress versions up to, and including, 3.5.2
Description The issue allows for Remote Code Execution via the swp url parameter, enabling attackers to execute code on the server.
Recommendations For versions up to, and including, 3.5.2, update to a version higher than 3.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the swp url parameter until a patch is available.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-4434

Affected Products

Social Warfare