ajax-extend <= 1.0 - Unauthenticated Remote Code Execution
criticalThe ajax-extend plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0 via the ajax_operation function. This is due to plugin not properly restricting user input to call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2024