What the vulnerability does
01Description
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
Explanation of Vulnerability in Simple Terms
02Summary
Social Warfare versions 4.4.6.4 through 4.4.7.1 contain a critical vulnerability that allows unauthenticated attackers to run arbitrary code on affected WordPress sites. The vulnerability requires no user interaction and can be exploited remotely over the network. All sites running the affected versions are at immediate risk of complete compromise.
What an attacker can do
03Attacker Capabilities
Run arbitrary PHP code on the site and take complete control of it.
Potential impact on your site
04Site Impact
Complete site compromise, data theft, malware installation, and loss of control over the WordPress installation.
Conditions required to exploit
05Prerequisites
None. The vulnerability can be exploited by anyone on the internet without authentication or user interaction.
Key dates
06Disclosure timeline
June 25, 2024
CVE published
August 1, 2024
Record updated