WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · wpmudev-updatespublic PoCs found — 1
cve_referencewpscan.com/vulnerability/8dae5fbf-2e9d-4978-b97d-a20e076cd309/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.