Back to overview

CVE-2024-6297

CRITICAL
10.0
CVSS 3.1
Description
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

Metadata

CVE ID
CVE-2024-6297
State
PUBLISHED
Assigner
Wordfence
Reserved
2024-06-25 03:30 UTC
Published
2024-06-25 03:30 UTC
Last updated
2024-08-01 21:33 UTC
Vendor / Product
warfareplugins / Social Sharing Plugin – Social Warfare
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (5)
VendorProductPlatformVersions
blazeretail BLAZE Retail Widget 2.2.5 ≤ 2.5.2
pedrogusmao02 Wrapper Link Elementor 1.0.2 ≤ 1.0.3
stuartobrien Simply Show Hooks 1.2.1 ≤ 1.2.2
themerex Contact Form 7 Multi-Step Addon 1.0.4 ≤ 1.0.5
warfareplugins Social Sharing Plugin – Social Warfare 4.4.6.4 ≤ 4.4.7.1
Weakness (CWE)
CWESourceDescription
cna CWE-506 Embedded Malicious Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview