WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
Vulnerability Description
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20251
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- sucuri.net @sucurisecurity
References
More from Themeisle
View All →Affected Vendor
Themeisle
View all reports →