PT-2026-71010 · WordPress · Wpmudev-Updates
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpmudev-updates WordPress plugin versions prior to 5.0.1
Description
The plugin fails to verify the integrity of packages installed via its remote management interface and does not protect requests against replay attacks. This allows an attacker who obtains or replays a valid signed management request to perform remote code execution by installing and executing arbitrary code.
Recommendations
Update wpmudev-updates WordPress plugin to version 5.0.1 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpmudev-Updates