NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4
unknown
[en] The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (Wo...
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- Oct 16, 2024
CVE-2021-4451 on NVD →
NinjaFirewall <= 4.3.3 - Authenticated PHAR Deserialization
medium
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPre...
- CVSS:
- 6.6
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- May 30, 2021
CVE-2021-4451 on NVD →
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4
unknown
Authenticated PHAR Deserialization vulnerability discovered by Chloe Chamberland in WordPress NinjaFirewall plugin (versions <= 4.3.3).
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- May 30, 2021
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4
unknown
The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPre...
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- May 30, 2021
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4
unknown
The plugin was affected by a PHAR deserialisation issue, which may allow admin users to execute arbitrary code on the remote host. The plugin did not have a POP chain available, so another plugin/theme with one would need to be present, other conditions for the attack are described in the vendor's post.
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database