CVE-2017-20086: VaultPress Plugin code injection
Published Jun 23, 2022
·Updated
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
Affected Software
1 affected component
Automattic Vaultpress Wordpress=1.8.4
Event History
Jun 23, 2022
CVE Published
via MITRE·04:20 AM
Data Sourced
via MITRE·04:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-20086?
The severity of CVE-2017-20086 is classified as high.
2
How does CVE-2017-20086 affect VaultPress Plugin 1.8.4?
CVE-2017-20086 affects an unknown part of VaultPress Plugin 1.8.4, leading to code injection.
3
Can CVE-2017-20086 be exploited remotely?
Yes, CVE-2017-20086 can be exploited remotely.
4
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2017-20086?
The CWE ID associated with CVE-2017-20086 is CWE-94.
5
How can I fix CVE-2017-20086 in VaultPress Plugin 1.8.4?
To fix CVE-2017-20086 in VaultPress Plugin 1.8.4, update to a version that addresses the vulnerability.