CVE-2011-4342: Code Injection
Published Oct 8, 2012
·Updated
PHP remote file inclusion vulnerability in wpxmlexport.php in the BackWPup plugin before 1.7.2 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpabs parameter.
Affected Software
4 affected components
BackWPup BackWPup<=1.7.1
WordPress WordPress
All of the following
BackWPup BackWPup<=1.7.1
WordPress WordPress
Event History
Oct 8, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4342?
CVE-2011-4342 has a high severity rating due to its potential for remote exploitation and arbitrary code execution.
2
How do I fix CVE-2011-4342?
To fix CVE-2011-4342, update the BackWPup plugin to version 1.7.2 or later.
3
What vulnerable versions are affected by CVE-2011-4342?
CVE-2011-4342 affects BackWPup plugin versions prior to 1.7.2.
4
Can CVE-2011-4342 be exploited remotely?
Yes, CVE-2011-4342 allows remote attackers to exploit the vulnerability via a crafted URL.
5
Which plugin is associated with CVE-2011-4342?
CVE-2011-4342 is associated with the BackWPup plugin for WordPress.