What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1.8.
Explanation of Vulnerability in Simple Terms
WP Booklet versions up to 2.1.8 contain a code injection vulnerability that allows authenticated users with low privileges to run their own PHP code on the site. The vulnerability exists due to insufficient input validation and affects the entire site when exploited. A patch version has not been publicly identified.
What an attacker can do
Run arbitrary PHP code on the site with the privileges of the web server.
Potential impact on your site
An authenticated attacker can compromise the entire site, steal data, modify content, or install malware.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities