PHP Remote File Inclusion Vulnerability in Allwebmenus Plugin for WordPress
CVE-2011-3981

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
4 October 2011

Summary

The Allwebmenus plugin for WordPress contains a PHP remote file inclusion vulnerability found in the actions.php file. This security flaw permits remote attackers to execute arbitrary PHP code by supplying a malicious URL in the abspath parameter. Successful exploitation can lead to unauthorized system access, data theft, and further compromise of the affected WordPress site.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.