CVE-2016-10960
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 9.0%
from disclosure to weapon
Published on NVDSep 16
VulnCheck+2214d
exploitation probability
9.0%top 5% of all CVEs
observed exploitation
yesVulnCheck
The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.
Affected products
n/a · n/a