What the vulnerability does
01Description
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
Explanation of Vulnerability in Simple Terms
The Spider Analyser WordPress plugin through version 2.1.3 contains a code injection vulnerability that allows unauthenticated attackers to run arbitrary PHP code on the site without user interaction. The vulnerability stems from insufficient input validation in the plugin's core functionality. An attacker can exploit this remotely over the network to gain full control of the WordPress installation, including reading sensitive data, modifying content, and disrupting service.
What an attacker can do
Run arbitrary PHP code on the site and take complete control of the WordPress installation.
Potential impact on your site
Complete compromise of the WordPress site, including data theft, malware injection, and service disruption.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities