VaultPress <=1.9 - Remote Code Execution
critical
The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.9 via the openssl_verify function. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 1.9
- Fixed in:
- 1.9.1
- Disclosed:
- Sep 16, 2017
VaultPress <= 1.8.6 - Remote Code Execution
high
The VaultPress plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.8.6 via the vaultpress/class.vaultpress-ixr-ssl-client.php file. This allows unauthenticated attackers to execute code on the server. This requires a man in the middle attack to be successful as an attacker ne...
- CVSS:
- 8.1
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.7
- Disclosed:
- Mar 1, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database