Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-44223

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.387
EPSS Ranking 97.0%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 7.5
Products affected by CVE-2021-44223


Contact Us

Shodan ® - All rights reserved