Arbitrary Command Execution Vulnerability in iMember360 for WordPress
CVE-2014-8949
Currently unrated
Summary
The iMember360 plugin versions 3.8.012 through 3.9.001 for WordPress features a vulnerability that allows remote authenticated administrators to execute arbitrary commands. This is enabled through improperly handled shell metacharacters in the i4w_trace parameter. The issue poses additional concerns as it can potentially be exploited in conjunction with a related vulnerability, facilitating remote code execution by attackers. Overall, this vulnerability may lead to serious security breaches, given the unclear scope regarding privilege escalation.
References
EPSS Score
7% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved