First published: Tue Jan 16 2024(Updated: )
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weblizar School Management | <9.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1609 is classified as a critical severity vulnerability due to its ability to allow unauthenticated attackers to execute arbitrary PHP code.
To fix CVE-2022-1609, update the Weblizar School Management plugin to version 9.9.7 or later.
CVE-2022-1609 allows an unauthenticated attacker to execute arbitrary PHP code on the site through an obfuscated backdoor in the plugin.
CVE-2022-1609 affects versions of the Weblizar School Management plugin before 9.9.7.
The backdoor in CVE-2022-1609 is obfuscated, making it challenging to detect without thorough code review.