Plainview Activity Monitor < 20180826 - Remote Command Injection
highThe Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request.
- CVSS:
- 8.8
- Affected:
- up to 20180826
- Fixed in:
- 20180826
- Disclosed:
- Aug 26, 2018