PT-2025-51290 · WordPress · Wp2Fac
Published
2025-12-15
·
Updated
2025-12-21
·
CVE-2023-53872
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wp2Fac version 1.0
Description
The software contains an OS command injection issue in the
send.php endpoint. This allows remote attackers to execute arbitrary system commands. The issue occurs because attackers can inject shell commands through the numara parameter by appending shell commands with '&' operators. This enables the execution of malicious code.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the
send.php endpoint. Avoid using the numara parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp2Fac