Unrated severityNVD Advisory· Published Nov 25, 2021· Updated Aug 4, 2024
CVE-2021-44223
CVE-2021-44223
Description
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Affected products
3- WordPress/WordPressdescription
- osv-coords2 versions
< 5.8.0+ 1 more
- (no CPE)range: < 5.8.0
- (no CPE)range: < 5.8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- make.wordpress.org/core/2021/06/29/introducing-update-uri-plugin-header-in-wordpress-5-8/mitrex_refsource_MISC
- vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.