← back
CVE-2016-10960observed exploitation

CVE-2016-10960

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.0%
from disclosure to weapon
Published on NVDSep 16
VulnCheck+2214d
exploitation probability
9.0%top 5% of all CVEs
observed exploitation
yesVulnCheck
The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.
Affected products
n/a · n/a