WPCargo < 6.9.0 - Unauthenticated RCE
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 56%
from disclosure to weapon104 days
Published on NVDMar 14
1st PoC+104d
VulnCheck+626d
exploitation probability
56%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
Affected products
Unknown · WPCargo Track & Tracepublic PoCs found — 1
vulncheckvulncheck.com/xdb/4f7e5614ce99unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.