First published: Wed Jan 17 2024(Updated: )
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Warfare Plugins Social Warfare | <3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-4434 is critical as it allows for Remote Code Execution on affected servers.
To fix CVE-2021-4434, update the Social Warfare plugin to version 3.5.3 or later.
CVE-2021-4434 affects users of the Social Warfare plugin for WordPress in versions up to and including 3.5.2.
If CVE-2021-4434 is exploited, attackers can execute arbitrary code on the affected WordPress server.
CVE-2021-4434 was publicly disclosed in 2021.