🔐 CVE Alert

CVE-2024-6297

CRITICAL 10.0

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.

Vendor warfareplugins
Product social sharing plugin – social warfare
Published Jun 25, 2024
Last Updated Aug 1, 2024
Stay Ahead of the Next One

Get instant alerts for warfareplugins social sharing plugin – social warfare

Be the first to know when new critical vulnerabilities affecting warfareplugins social sharing plugin – social warfare are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

warfareplugins / Social Sharing Plugin – Social Warfare
4.4.6.4 ≤ 4.4.7.1
themerex / Contact Form 7 Multi-Step Addon
1.0.4 ≤ 1.0.5
stuartobrien / Simply Show Hooks
1.2.1 ≤ 1.2.2
pedrogusmao02 / Wrapper Link Elementor
1.0.2 ≤ 1.0.3
blazeretail / BLAZE Retail Widget
2.2.5 ≤ 2.5.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/56d24bc8-4a1a-4e60-aec5-960703a6058a?source=cve wordpress.org: https://wordpress.org/support/topic/a-security-message-from-the-plugin-review-team/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L54 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/social-warfare/tags/4.4.6.4/trunk/social-warfare.php#L583 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3105893/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3106042%40social-warfare&new=3106042%40social-warfare&sfp_email=&sfph_mail= plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/simply-show-hooks/trunk/index.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/contact-form-7-multi-step-addon/trunk/trx-contact-form-7-multi-step-addon.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wrapper-link-elementor/trunk/wrapper.php?rev=3106508 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/blaze-widget/trunk/blaze_widget.php