CVE-2024-6297
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
| Vendor | warfareplugins |
| Product | social sharing plugin – social warfare |
| Published | Jun 25, 2024 |
| Last Updated | Aug 1, 2024 |
Stay Ahead of the Next One
Get instant alerts for warfareplugins social sharing plugin – social warfare
Be the first to know when new critical vulnerabilities affecting warfareplugins social sharing plugin – social warfare are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
warfareplugins / Social Sharing Plugin – Social Warfare
4.4.6.4 ≤ 4.4.7.1
themerex / Contact Form 7 Multi-Step Addon
1.0.4 ≤ 1.0.5
stuartobrien / Simply Show Hooks
1.2.1 ≤ 1.2.2
pedrogusmao02 / Wrapper Link Elementor
1.0.2 ≤ 1.0.3
blazeretail / BLAZE Retail Widget
2.2.5 ≤ 2.5.2
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/56d24bc8-4a1a-4e60-aec5-960703a6058a?source=cve wordpress.org: https://wordpress.org/support/topic/a-security-message-from-the-plugin-review-team/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L54 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L583 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3105893/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3106042%40social-warfare&new=3106042%40social-warfare&sfp_email=&sfph_mail= plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/simply-show-hooks/trunk/index.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/contact-form-7-multi-step-addon/trunk/trx-contact-form-7-multi-step-addon.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wrapper-link-elementor/trunk/wrapper.php?rev=3106508 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/blaze-widget/trunk/blaze_widget.php