WordPress Plugin Vulnerabilities

Multiple Plugins - Unauthenticated RCE via PHPUnit

Description

There was an Unauthenticated Remote Code Execution (RCE) vulnerability in PHPUnit, a widely used testing framework for PHP.

This vulnerability has been seen exploited in the wild.

Proof of Concept

Affects Plugins

Fixed in 2.2.1
No known fix
Fixed in 1.1.12

References

Classification

Type
RCE
OWASP top 10
CWE

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2017-08-26 (about 8 years ago)
Added
2020-03-16 (about 6 years ago)
Last Updated
2020-11-07 (about 5 years ago)

Other