Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-44223

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.238
EPSS Ranking 95.8%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 7.5
Products affected by CVE-2021-44223


Contact Us

Shodan ® - All rights reserved