First published: Thu Nov 25 2021(Updated: )
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WordPress | <5.8 | |
<5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WordPress vulnerability is CVE-2021-44223.
CVE-2021-44223 has a severity level of critical, with a CVSS severity score of 9.8.
CVE-2021-44223 allows remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations.
WordPress versions before 5.8 are affected by CVE-2021-44223.
To mitigate CVE-2021-44223, update WordPress to version 5.8 or later, which includes support for the Update URI plugin header.