PT-2024-37520 · WordPress · Wordpress
Mrfoxtalbot
·
Published
2024-06-25
·
Updated
2026-03-08
·
CVE-2024-6297
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WordPress plugins (affected versions not specified)
Description:
A malicious threat actor has compromised the source code of various WordPress plugins hosted on WordPress.org, injecting malicious PHP scripts. These scripts exfiltrate database credentials, create new malicious administrator users, and send the data back to a server. It is estimated that over 100,000 websites are affected. The issue concerns supply chain techniques and affects the e-commerce industry.
Recommendations:
As a temporary workaround, consider uninstalling the affected plugins for the time being and running a complete malware scan.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress