Vulnerability Intelligence Report
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
CVE-2024-6297
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:1.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-506 ↗CWE-506 Embedded Malicious Code
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| warfareplugins | Social Sharing Plugin – Social Warfare | 4.4.6.4 <= 4.4.7.1 (affected) |
| themerex | Contact Form 7 Multi-Step Addon | 1.0.4 <= 1.0.5 (affected) |
| stuartobrien | Simply Show Hooks | 1.2.1 <= 1.2.2 (affected) |
| pedrogusmao02 | Wrapper Link Elementor | 1.0.2 <= 1.0.3 (affected) |
| blazeretail | BLAZE Retail Widget | 2.2.5 <= 2.5.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.011%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Wordfence · Vendor · USA |
| Reserved | 2024-06-25T03:30:37 |
| Published | 2024-06-25T03:30:37 |
| Last Updated | 2024-08-01T21:33:05 |
Community Chatter & Buzz