Arbitrary Command Execution Vulnerability in iMember360 for WordPress
CVE-2014-8949

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 November 2014

Summary

The iMember360 plugin versions 3.8.012 through 3.9.001 for WordPress features a vulnerability that allows remote authenticated administrators to execute arbitrary commands. This is enabled through improperly handled shell metacharacters in the i4w_trace parameter. The issue poses additional concerns as it can potentially be exploited in conjunction with a related vulnerability, facilitating remote code execution by attackers. Overall, this vulnerability may lead to serious security breaches, given the unclear scope regarding privilege escalation.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.